Impact
FlexNet Publisher lmadmin contains a hardcoded authentication bypass in its SOAP handler that allows an unauthenticated user to obtain a privileged administrator session. This bypass, classified as CWE‑288, gives an attacker control over the system similar to having root or administrator rights, enabling configuration changes, installation of software, or potential code execution. The compromise directly threatens confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Flexera’s FlexNet Publisher, specifically the lmadmin component. No specific product version information is provided, so any deployment using the lmadmin SOAP service is potentially impacted.
Risk and Exploitability
The CVSS score of 9.3 labels the weakness as critical, while the EPSS score is unavailable and the issue is not listed in CISA KEV. The likely attack vector is a network‑accessible SOAP endpoint; no credentials are required due to the hardcoded bypass, suggesting that the exploit can be performed remotely from an attacker who can reach the service in the network. This combination of high severity, low effort to exploit, and complete privilege elevation leads to an elevated risk level.
OpenCVE Enrichment