Authentication Bypass Vulnerability in FlexNet Publisher by Revenera
CVE-2026-19572

9.3CRITICAL

Key Information:

Vendor

Flexera

Vendor
CVE Published:
7 October 2026

What is CVE-2026-19572?

A significant security issue has been discovered in FlexNet Publisher lmadmin, specifically within its SOAP handler. This vulnerability allows an unauthenticated individual to exploit hardcoded credentials, gaining unauthorized access to a privileged administrator session without necessitating valid authentication. Such a flaw presents severe risks as it compromises the integrity and security of the affected systems. Users of FlexNet Publisher must take immediate steps to mitigate this vulnerability as outlined in official communications from Revenera.

Affected Version(s)

FlexNet Publisher Windows 0 <= 11.19.11

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.