File Parsing Vulnerability in CNCSoft-G2 by Delta Electronics
CVE-2026-3094

7.8HIGH

Key Information:

Vendor

Deltaww

Vendor
CVE Published:
4 March 2026

What is CVE-2026-3094?

Delta Electronics' CNCSoft-G2 software is susceptible to a vulnerability stemming from insufficient validation of user-supplied file inputs. An attacker can exploit this flaw by tricking a user into opening a specially crafted malicious file, potentially leading to unauthorized code execution within the context of the application’s process. Users and administrators should remain vigilant and apply necessary updates to mitigate associated risks.

Affected Version(s)

CNCSoft-G2 0 < 2.1.0.39

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Natnael Samson (@NattiSamson) working with TrendAI Zero Day Initiative
Israel Bentley of CISA
.