Input Verification Flaw in Cybozu Garoon Product by Cybozu
CVE-2026-22888
6.9MEDIUM
What is CVE-2026-22888?
An improper input verification vulnerability has been discovered in Cybozu Garoon versions 5.0.0 through 6.0.3. This issue could allow attackers to modify portal settings without authorization, potentially blocking legitimate users from accessing the product. It is crucial for users to review their current version and evaluate potential impacts on system security.
Affected Version(s)
Cybozu Garoon 5.0.0 to 6.0.3
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved