Description
A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.
Published: 2026-10-07
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized Admin Access
Action: Immediate Patch
AI Analysis

Impact

FlexNet Publisher lmadmin contains a hardcoded authentication bypass in its SOAP handler that allows an unauthenticated user to obtain a privileged administrator session. This bypass, classified as CWE‑288, gives an attacker control over the system similar to having root or administrator rights, enabling configuration changes, installation of software, or potential code execution. The compromise directly threatens confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerability affects Flexera’s FlexNet Publisher, specifically the lmadmin component. No specific product version information is provided, so any deployment using the lmadmin SOAP service is potentially impacted.

Risk and Exploitability

The CVSS score of 9.3 labels the weakness as critical, while the EPSS score is unavailable and the issue is not listed in CISA KEV. The likely attack vector is a network‑accessible SOAP endpoint; no credentials are required due to the hardcoded bypass, suggesting that the exploit can be performed remotely from an attacker who can reach the service in the network. This combination of high severity, low effort to exploit, and complete privilege elevation leads to an elevated risk level.

Generated by OpenCVE AI on October 7, 2026 at 05:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied patch or upgrade to the latest FlexNet Publisher release that removes the hardcoded authentication bypass in lmadmin.
  • If the SOAP service is not required, disable it or restrict it through firewall rules to trusted IP ranges only.
  • Continuously monitor system logs for unexpected lmadmin sessions and enforce strict change‑control procedures on configuration changes.

Generated by OpenCVE AI on October 7, 2026 at 05:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Flexera
Flexera flexnet Publisher
Vendors & Products Flexera
Flexera flexnet Publisher

Wed, 07 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.
Title FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Flexera Flexnet Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: flexera

Published:

Updated: 2026-10-07T04:04:19.609Z

Reserved: 2026-08-11T19:17:54.002Z

Link: CVE-2026-19572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T04:18:09.053

Modified: 2026-10-07T04:18:09.053

Link: CVE-2026-19572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:45:13Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel