ZeroHour

CVE-2026-66840

Unauthenticated Sensitive System Information Disclosure in XING CPTrans-ME-X

CVSS 4.0
8.7 high
EPSS
<1%p18
Published
()
Modified
AI analysis

XING CPTrans-ME-X contains an exposure of sensitive system information to an unauthorized control sphere (CWE-497), meaning an attacker can retrieve sensitive system details that should not be exposed. Per the CVSS 4.0 vector, the issue is reachable over a network (AV:N) without privileges, user interaction, or exploit complexity, so a remote, unauthenticated actor could trigger the leak. The impact is limited to confidentiality (VC:H) — the attacker gains sensitive system information, with no integrity or availability impact. Anyone operating an affected instance of CPTrans-ME-X is potentially affected, though the advisory data does not specify which versions are impacted. There is currently no public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.3%, indicating no known exploitation at this time.

What to do: Check with the vendor (coordinated via JPCERT) for an updated release that resolves CVE-2026-66840, since no fixed version is specified in the available data. In the meantime, restrict network access to the CPTrans-ME-X service to trusted hosts and review whether it is exposed to the internet. Inspect systems for signs that sensitive configuration or system information has been queried by unauthenticated clients.

Affected
XING CPTrans-ME-X
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.

Weakness
CWE-497
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.