CVE-2026-66840
—Unauthenticated Sensitive System Information Disclosure in XING CPTrans-ME-X
XING CPTrans-ME-X contains an exposure of sensitive system information to an unauthorized control sphere (CWE-497), meaning an attacker can retrieve sensitive system details that should not be exposed. Per the CVSS 4.0 vector, the issue is reachable over a network (AV:N) without privileges, user interaction, or exploit complexity, so a remote, unauthenticated actor could trigger the leak. The impact is limited to confidentiality (VC:H) — the attacker gains sensitive system information, with no integrity or availability impact. Anyone operating an affected instance of CPTrans-ME-X is potentially affected, though the advisory data does not specify which versions are impacted. There is currently no public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.3%, indicating no known exploitation at this time.
What to do: Check with the vendor (coordinated via JPCERT) for an updated release that resolves CVE-2026-66840, since no fixed version is specified in the available data. In the meantime, restrict network access to the CPTrans-ME-X service to trusted hosts and review whether it is exposed to the internet. Inspect systems for signs that sensitive configuration or system information has been queried by unauthenticated clients.
| XING CPTrans-ME-X | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
- Weakness
- CWE-497
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.