Description
ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attacker to retrieve plaintext service account and SMTP credentials by requesting specific XML files from the webroot.
This issue has been fixed in version 2.4.18.029
Published: 2026-07-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the vulnerability permits unauthenticated HTTP access to specific XML files under the web root, which contain plaintext service account and SMTP credentials. Attackers can retrieve these credentials without authentication, compromising confidentiality and enabling further account takeover or malicious mail sending. This weakness is classified as CWE-522.

Affected Systems

The vulnerability affects ICU Scandinavia Boomerang installations. The fix was delivered in version 2.4.18.029 and later releases address the issue.

Risk and Exploitability

Based on the description, it is inferred that attackers can exploit it remotely by issuing simple HTTP requests to the exposed XML files, requiring no authentication. The CVSS score of 7.1 reflects a moderate to high risk. The EPSS score of less than 1% indicates a low but nonzero exploitation probability. The vulnerability is not listed in CISA KEV. Given the sensitive nature of the credentials, the confidentiality impact is considerable.

Generated by OpenCVE AI on July 31, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Boomerang to version 2.4.18.029 or later.
  • Remove or encrypt the credential XML files from the web root so they are no longer served as static content.
  • Configure network controls to block or require authentication for HTTP access to the web root before applying the patch.
  • Audit and rotate all exposed service account and SMTP credentials to limit potential damage if compromise already occurred.

Generated by OpenCVE AI on July 31, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Icu Scandinavia
Icu Scandinavia boomerang
Vendors & Products Icu Scandinavia
Icu Scandinavia boomerang

Thu, 16 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attacker to retrieve plaintext service account and SMTP credentials by requesting specific XML files from the webroot. This issue has been fixed in version 2.4.18.029
Title Credential exposure in ICU Scandinavia Boomerang
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Icu Scandinavia Boomerang
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-07-15T13:02:49.266Z

Reserved: 2026-05-14T14:11:53.521Z

Link: CVE-2026-46458

cve-icon Vulnrichment

Updated: 2026-07-15T13:02:45.510Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:45:04Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials