File Parsing Vulnerability in CNCSoft-G2 by Delta Electronics
CVE-2026-3094
7.8HIGH
What is CVE-2026-3094?
Delta Electronics' CNCSoft-G2 software is susceptible to a vulnerability stemming from insufficient validation of user-supplied file inputs. An attacker can exploit this flaw by tricking a user into opening a specially crafted malicious file, potentially leading to unauthorized code execution within the context of the application’s process. Users and administrators should remain vigilant and apply necessary updates to mitigate associated risks.
Affected Version(s)
CNCSoft-G2 0 < 2.1.0.39
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Natnael Samson (@NattiSamson) working with TrendAI Zero Day Initiative
Israel Bentley of CISA
