Missing Authentication Flaw in CAYIN CMS-WS and CMS-SE Products by CAYIN Technology
CVE-2026-80234

6.9MEDIUM

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2026-80234?

CAYIN CMS-WS and CMS-SE developed by CAYIN Technology are susceptible to a missing authentication vulnerability. This security flaw enables unauthenticated remote attackers to access and obtain media file lists through certain functionalities, leading to potential partial information disclosure. Organizations using these products should evaluate their security measures to protect sensitive data from unauthorized access.

Affected Version(s)

CAYIN CMS-SE 0 <= 11.0.25336

CAYIN CMS-WS 0 <= 1.0.25336

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.