Remote Code Execution Vulnerability in Digital Knowledge's KnowledgeDeliver Software
CVE-2026-5426
Key Information:
- Vendor
Digital Knowledge
- Status
- Vendor
- CVE Published:
- 16 April 2026
Badges
What is CVE-2026-5426?
A hard-coded machineKey value in Digital Knowledge's KnowledgeDeliver software, prior to February 24, 2026, enables attackers to bypass ViewState validation. This vulnerability can be exploited through malicious ViewState deserialization attacks, allowing unauthorized remote code execution. Proper handling and configuration of machineKey values are critical to mitigate this risk.
Affected Version(s)
KnowledgeDeliver 0 < 20260224
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
CVE-2026-5426 enabled KnowledgeDeliver LMS attacks before February 24, 2026, leading to Cobalt Strike infections.
13 hours ago
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- π°
Used in Ransomware
- πΎ
Exploit known to exist
- π°
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
