CVE-2026-18188: A format string vulnerability was found in the Rsync Backup on the ADM
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected backup component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18188?
The severity of CVE-2026-18188 is classified as high with a CVSS score of 7.1.
How do I fix CVE-2026-18188?
To fix CVE-2026-18188, update your ADM Rsync Backup to the latest version provided by the vendor.
What can an attacker do with CVE-2026-18188?
An authenticated attacker can exploit CVE-2026-18188 to disclose sensitive memory information through unsafe format string operations.
How does CVE-2026-18188 affect my system?
CVE-2026-18188 can compromise the confidentiality of your system by allowing attackers to access memory information.
What component is affected by CVE-2026-18188?
CVE-2026-18188 specifically affects the Rsync Backup component on the ADM system.