GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
Update to version 20260108 or later.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drangsoft gcb/fcb Audit Software
|
|
| Vendors & Products |
Drangsoft gcb/fcb Audit Software
|
Tue, 17 Mar 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account. | |
| Title | DrangSoft|GCB/FCB Audit Software - Missing Authentication | |
| First Time appeared |
Drangsoft
Drangsoft gcb Fcb Audit Software |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:drangsoft:gcb_fcb_audit_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Drangsoft
Drangsoft gcb Fcb Audit Software |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-03-17T07:29:17.331Z
Reserved: 2026-03-17T06:59:57.728Z
Link: CVE-2026-4312
No data.
Status : Received
Published: 2026-03-17T08:15:57.417
Modified: 2026-03-17T08:15:57.417
Link: CVE-2026-4312
No data.
OpenCVE Enrichment
Updated: 2026-03-17T09:51:53Z
Weaknesses