Arbitrary Code Execution Vulnerability in eParakstītājs 3.0 for Windows
CVE-2026-0392

7.3HIGH

What is CVE-2026-0392?

eParakstītājs 3.0 for Windows prior to version 1.10.0 is susceptible to a security flaw that allows an attacker to execute arbitrary code on the host machine. The application fetches update descriptors over TLS but fails to authenticate or verify the integrity of these updates. Due to a permissive TrustManager and a HostnameVerifier, any TLS certificate is accepted, and the absence of digital signature verification on the update descriptor means a malicious redirect can lead the software to download and execute a compromised installer. This unchecked update mechanism poses serious risks, enabling man-in-the-middle attacks that could compromise users' systems.

Affected Version(s)

eParakstītājs 3.0 Windows 0 < 1.10.0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nils Putniņš, OffSeq (SIA SEQ)
.