CVE-2026-101083: PMWeb encryptionhelper.dll information disclosure
A security vulnerability has been detected in PMWeb v7.x/v8.x/v2025.x. Impacted is an unknown function in the library encryptionhelper.dll. Such manipulation leads to information disclosure. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which PMWeb deployments are in scope?
The affected release families are PMWeb v7.x, v8.x, and v2025.x. No more specific fixed or affected versions are provided.
Does exploitation require authentication or user interaction?
The available CVSS vector indicates that exploitation is network-accessible, requires low attack complexity, and requires neither privileges nor user interaction.
What is the known security impact?
The reported impact is information disclosure with low confidentiality impact. Integrity and availability impacts are not indicated by the supplied CVSS vector.
Is a vendor remediation available?
The supplied information does not identify a patch, workaround, or vendor response. It states that the vendor was contacted but did not respond.