CVE-2026-19572: FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability
Published Oct 7, 2026
·Updated
A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.
Affected Software
1 affected component
Flexera FlexNet Publisher lmadmin
Event History
Oct 7, 2026
CVE Published
via MITRE·04:04 AM
Data Sourced
via MITRE·04:04 AM
DescriptionWeakness
Data Sourced
via NVD·04:18 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require valid lmadmin credentials or user interaction?
No. The vulnerability can be exploited by an unauthenticated attacker without providing valid credentials, and the CVSS vector indicates no user interaction is required.
2
What level of access could an attacker gain?
Successful exploitation could provide a privileged administrator session.