Incorrect Authorization Vulnerability in Wertheim SafeController Software
CVE-2026-34023

7.1HIGH

What is CVE-2026-34023?

The Wertheim SafeController Software features an incorrect authorization vulnerability within its WebSocket communication framework, specifically in the SafeMessageBroker component. This flaw allows an authenticated attacker with low-privileged branch user credentials to manipulate WebSocket messages. By specifying controller identifiers associated with different branches, the attacker can access restricted functions and resources. Consequently, this exploitation may lead to activities such as activating secure boxes outside of the authorized branch, compromising the security boundaries established within the branch infrastructure.

Affected Version(s)

Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Hager, SEC Consult Vulnerability Lab
Gorazd Jank, SEC Consult Vulnerability Lab
Philipp Espernberger, SEC Consult Vulnerability Lab
.