Description
CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.
Published: 2026-08-26
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unverified remote attackers can exploit a missing authentication flaw in CAYIN CMS-WS and CMS-SE to retrieve lists of media files. This vulnerability allows an attacker to obtain potentially sensitive information about the file structure and contents, constituting partial information disclosure. The weakness is a classic Missing Authentication issue, classified as CWE‑306.

Affected Systems

The flaw afflicts CAYIN Technology’s CAYIN CMS‑WS and CAYIN CMS‑SE products. All releases of CMS‑WS prior to 1.0.26198 and all releases of CMS‑SE prior to 11.0.26198 are vulnerable. Updating to the specified or later versions mitigates the issue.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity risk. The EPSS score is not published, and the vulnerability is not listed in the CISA KEV catalog, suggesting no immediate known widespread exploitation. The attack vector is remote; unauthenticated users can reach the affected endpoints over HTTP/HTTPS. While the flaw does not permit code execution, the disclosure of media file names can aid in planning further attacks against the system.

Generated by OpenCVE AI on August 26, 2026 at 09:23 UTC.

Remediation

Vendor Solution

Update CMS-WS to version 1.0.26198 or later Update CMS-SE to version 11.0.26198 or later


OpenCVE Recommended Actions

  • Upgrade CAYIN CMS‑WS to version 1.0.26198 or later
  • Upgrade CAYIN CMS‑SE to version 11.0.26198 or later
  • Configure the web application to enforce authentication for all routes that expose media file listings

Generated by OpenCVE AI on August 26, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.
Title CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-08-26T08:22:13.081Z

Reserved: 2026-08-26T05:58:50.007Z

Link: CVE-2026-80234

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T09:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function