Improper Access Control Vulnerability in SiteServer SSCMS by SiteServer
CVE-2026-82486

2.3LOW

Key Information:

Vendor

Siteserver

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82486?

A vulnerability has been identified in SiteServer SSCMS version 7.4.0, concerning the Agent Installation Workflow component. This flaw allows attackers to manipulate the SecurityKey argument, resulting in improper access controls. As a result, this could enable unauthorized remote access to sensitive functionalities within the system. Although the exploitation is regarded as complex, it poses a significant security threat due to its potential impact. The SiteServer development team was notified of this issue early on through an issue report, but to date, no formal response or remediation has been documented.

Affected Version(s)

SSCMS 7.4.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mofeifei (VulDB User)
VulDB CNA Team
.