Unauthorized Control Sphere Vulnerability in Pronetiqs IntraVUE
CVE-2026-28698

9.2CRITICAL

Key Information:

Vendor

Pronetiqs

Vendor
CVE Published:
23 July 2026

What is CVE-2026-28698?

Pronetiqs IntraVUE versions up to 3.2.1a14 contain a vulnerability that exposes sensitive system information to unauthorized entities. This flaw could enable unauthorized actors to gain access to critical filesystem structures, compromising the integrity and confidentiality of system operations.

Affected Version(s)

Panduit Intravue 0 <= 3.2.1a14

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phlebas of Lumintel reported this vulnerability to CISA
.