CVE-2026-18187: A format string vulnerability was found in the Internal Backup on the ADM
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18187?
CVE-2026-18187 has been rated with a high severity score of 7.1.
How do I fix CVE-2026-18187?
To fix CVE-2026-18187, update your ADM software to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-18187?
CVE-2026-18187 is classified as a format string vulnerability affecting the Internal Backup of the ADM.
Who can exploit CVE-2026-18187?
An authenticated attacker can exploit CVE-2026-18187 to potentially disclose sensitive memory information.
What impact does CVE-2026-18187 have on the system?
The impact of CVE-2026-18187 includes the risk of memory disclosure, which can lead to further attacks or data breaches.