Description
CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.
Published: 2026-08-26
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Partial Information Disclosure
Action: Patch
AI Analysis

Impact

Unverified remote attackers can exploit a missing authentication flaw in CAYIN CMS-WS and CMS-SE to retrieve lists of media files. This vulnerability allows an attacker to obtain potentially sensitive information about the file structure and contents, constituting partial information disclosure. The weakness is a classic Missing Authentication issue, classified as CWE‑306.

Affected Systems

The flaw afflicts CAYIN Technology’s CAYIN CMS‑WS and CAYIN CMS‑SE products. All releases of CMS‑WS prior to 1.0.26198 and all releases of CMS‑SE prior to 11.0.26198 are vulnerable. Updating to the specified or later versions mitigates the issue.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity risk. The EPSS score is not published, and the vulnerability is not listed in the CISA KEV catalog, suggesting no immediate known widespread exploitation. The attack vector is remote; unauthenticated users can reach the affected endpoints over HTTP/HTTPS. While the flaw does not permit code execution, the disclosure of media file names can aid in planning further attacks against the system.

Generated by OpenCVE AI on August 26, 2026 at 09:23 UTC.

Remediation

Vendor Solution

Update CMS-WS to version 1.0.26198 or later Update CMS-SE to version 11.0.26198 or later


OpenCVE Recommended Actions

  • Upgrade CAYIN CMS‑WS to version 1.0.26198 or later
  • Upgrade CAYIN CMS‑SE to version 11.0.26198 or later
  • Configure the web application to enforce authentication for all routes that expose media file listings

Generated by OpenCVE AI on August 26, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Cayin Technology
Cayin Technology cayin Cms-se
Cayin Technology cayin Cms-ws
Vendors & Products Cayin Technology
Cayin Technology cayin Cms-se
Cayin Technology cayin Cms-ws

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.
Title CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Cayin Technology Cayin Cms-se Cayin Cms-ws
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-08-26T13:57:58.236Z

Reserved: 2026-08-26T05:58:50.007Z

Link: CVE-2026-80234

cve-icon Vulnrichment

Updated: 2026-08-26T13:57:55.088Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T09:16:48.880

Modified: 2026-09-03T05:15:19.187

Link: CVE-2026-80234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:33:37Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function