Remote Code Execution Vulnerability in SCBE-AETHERMOORE Framework by ISS Dandavis
CVE-2026-57443

7.5HIGH

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-57443?

The SCBE-AETHERMOORE framework exposes a significant vulnerability through its AetherBrowser API server. Versions from 4.0.2 to 4.2.0 lack authentication on the critical endpoint POST /api/ops/check-email, allowing attackers to execute arbitrary code that connects to users' email accounts via IMAP. This breach exposes sensitive email metadata including sender details, subject lines, and body snippets, making it essential for users to upgrade to version 4.2.1, which mitigates this security flaw. With default server settings, this vulnerability becomes publicly accessible, raising concerns about data privacy and security.

Affected Version(s)

SCBE-AETHERMOORE >= 4.0.2, < 4.2.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.