CVE-2026-22888: High severity Cybozu Garoon vulnerability
Published Feb 2, 2026
·Updated
Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.
Affected Software
2 affected components
Cybozu Garoon>=5.0.0<=6.0.3
Cybozu Garoon>=5.0.0<6.0.3
Event History
Feb 2, 2026
CVE Published
via MITRE·06:37 AM
Data Sourced
via MITRE·06:37 AM
DescriptionSeverity
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22888?
CVE-2026-22888 is considered a high severity vulnerability due to its potential to allow unauthorized alteration of portal settings.
2
How do I fix CVE-2026-22888?
To fix CVE-2026-22888, you should update Cybozu Garoon to a version later than 6.0.3.
3
What is the impact of CVE-2026-22888?
The impact of CVE-2026-22888 includes potential unauthorized access and modification of user portal settings.
4
Which versions of Cybozu Garoon are affected by CVE-2026-22888?
CVE-2026-22888 affects Cybozu Garoon versions from 5.0.0 to 6.0.3.
5
Is there a workaround for CVE-2026-22888 if I cannot immediately upgrade?
Currently, there are no known workarounds for CVE-2026-22888 other than applying the update to a fixed version.