This CVE documents behavior observed in a client-hosted deployment running an unsupported legacy version of Originate Loans Peripherals with .NET Remoting ports exposed to an untrusted network. This is not a default or supported configuration. Customers running legacy versions should upgrade to a currently supported release and ensure .NET Remoting ports are restricted to trusted network segments. The finding does not apply to Fiserv-hosted environments.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 25 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
ssvc
|
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fiserv
Fiserv originate Loans Peripherals (formerly Velocity Services) -- Print Service Component |
|
| Vendors & Products |
Fiserv
Fiserv originate Loans Peripherals (formerly Velocity Services) -- Print Service Component |
Mon, 23 Feb 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Print Service component of Fiserv Originate Loans Peripherals (formerly Velocity Services) in unsupported version 2021.2.4 (build 4.7.3155.0011) uses deprecated .NET Remoting TCP channels that allow unsafe deserialization of untrusted data. When these services are exposed to an untrusted network in a client-managed deployment, an unauthenticated attacker can achieve remote code execution. Version 2021.2.4 is no longer supported by Fiserv. Customers should upgrade to a currently supported release (2025.1 or later) and ensure that .NET Remoting service ports are not exposed beyond trusted network boundaries. This CVE documents behavior observed in a client-hosted deployment running an unsupported legacy version of Originate Loans Peripherals with .NET Remoting ports exposed to an untrusted network. This is not a default or supported configuration. Customers running legacy versions should upgrade to a currently supported release and ensure .NET Remoting ports are restricted to trusted network segments. The finding does not apply to Fiserv-hosted environments. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-02-25T16:07:57.615Z
Reserved: 2026-01-02T15:00:02.871Z
Link: CVE-2026-21665
Updated: 2026-02-25T16:07:49.184Z
Status : Awaiting Analysis
Published: 2026-02-23T23:16:15.710
Modified: 2026-02-25T17:25:37.403
Link: CVE-2026-21665
No data.
OpenCVE Enrichment
Updated: 2026-02-24T09:54:36Z