Impact
The vulnerability is a Missing Authentication flaw in DrangSoft GCB/FCB Audit Software that allows unauthenticated remote attackers to call specific APIs and create a new administrative account. The flaw, classified as CWE-306, grants the attacker the ability to gain administrative privileges without prior authentication, effectively bypassing all security controls and enabling full control over the affected system.
Affected Systems
Affected software is DrangSoft GCB/FCB Audit Software. The official solution specifies updating to version 20260108 or later; specific older versions are not listed, so all releases prior to that update are considered vulnerable.
Risk and Exploitability
The CVSS base score is 9.3, indicating critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KeV catalog. The attack vector is remote via unauthenticated API calls, making it highly likely that attackers can exploit the flaw without additional conditions.
OpenCVE Enrichment