Description
A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-30
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability was discovered in SiteServer SSCMS 7.4.0 that allows an attacker to manipulate the SecurityKey argument within the Agent Installation Workflow component. By tampering with this argument, the system fails to enforce proper access controls, enabling an attacker to gain unauthorized privileges or execute actions that should be restricted. The weakness aligns with CWE-266 and CWE-284, both related to improper use of privileged permissions and insufficient access controls. This flaw permits remote exploitation, meaning that an attacker can trigger the vulnerability over the network without needing local access.

Affected Systems

The affected product is SiteServer SSCMS, specifically version 7.4.0. The vulnerability exists in the Agent Installation Workflow component of this version. Users running 7.4.0 are potentially at risk. No other versions are specifically identified, but the impact is limited to the stated iteration.

Risk and Exploitability

The CVSS score is 2.3, indicating low overall severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. While the attack has high complexity and is considered difficult, the exploit remains possible from a remote location. The lack of a public patch and the low CVSS suggest that the risk is modest, but the possibility of unauthorized access warrants monitoring and mitigative action.

Generated by OpenCVE AI on August 30, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the latest SiteServer SSCMS releases and security advisories for a patch that corrects the SecurityKey access control problem, and upgrade to that version if available.
  • Restrict access to the Agent Installation Workflow endpoint to authenticated administrators only, and enforce strict role‑based access controls to prevent unauthorized manipulation of the SecurityKey argument.
  • Monitor incoming traffic and server logs for suspicious requests that alter the SecurityKey parameter, and configure alerts or blocking rules to respond to such activity promptly.

Generated by OpenCVE AI on August 30, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The project was informed of the problem early through an issue report but has not responded yet.
Title SiteServer SSCMS Agent Installation Workflow access control
First Time appeared Sscms
Sscms sscms
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:sscms:sscms:*:*:*:*:*:*:*:*
Vendors & Products Sscms
Sscms sscms
References
Metrics cvssV2_0

{'score': 5.1, 'vector': 'AV:N/AC:H/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-30T09:15:06.954Z

Reserved: 2026-08-29T16:15:17.563Z

Link: CVE-2026-82486

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T10:17:14.843

Modified: 2026-08-30T10:17:14.843

Link: CVE-2026-82486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T10:30:16Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control