Information Disclosure Vulnerability in MingSoft MCMS by MingSoft
CVE-2026-19357

6.9MEDIUM

Key Information:

Vendor

Mingsoft

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19357?

A security vulnerability identified in MingSoft MCMS versions up to 3.0.6 affects an unknown functionality within the /mdiy/form/get file of the ms-mdiy component. This vulnerability allows for information disclosure, which can be exploited remotely. There has been public release of the exploit method, posing a significant risk to affected users. Despite attempts to notify the vendor about this critical issue, there has been no response. Organizations utilizing this product should take immediate steps to assess their exposure and implement necessary protections.

Affected Version(s)

MCMS 3.0.0

MCMS 3.0.1

MCMS 3.0.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

murkfox (VulDB User)
VulDB CNA Team
.