Input Verification Flaw in Cybozu Garoon Product by Cybozu
CVE-2026-22888

6.9MEDIUM

Key Information:

Vendor

Cybozu

Vendor
CVE Published:
2 February 2026

What is CVE-2026-22888?

An improper input verification vulnerability has been discovered in Cybozu Garoon versions 5.0.0 through 6.0.3. This issue could allow attackers to modify portal settings without authorization, potentially blocking legitimate users from accessing the product. It is crucial for users to review their current version and evaluate potential impacts on system security.

Affected Version(s)

Cybozu Garoon 5.0.0 to 6.0.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.