CVE-2026-24936: An improper input validation vulnerability was found in ADM while joining a AD Domain.
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data to any file on the system. By exploiting this vulnerability, attackers can overwrite critical system files, leading to a complete system compromise. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24936?
The severity of CVE-2026-24936 is classified as high due to its potential to allow remote attackers to exploit improper input validation.
What does CVE-2026-24936 affect?
CVE-2026-24936 affects specific versions of the ADM software while joining an Active Directory (AD) Domain.
How do I fix CVE-2026-24936?
To fix CVE-2026-24936, ensure you update the ADM software to a version that addresses this vulnerability.
Can CVE-2026-24936 be exploited remotely?
Yes, CVE-2026-24936 can be exploited remotely by an unauthenticated attacker.
What versions of ADM are vulnerable to CVE-2026-24936?
Versions of ADM from 4.1.0 to 4.3.3.ROF1 and 5.0.0 to 5.1.1.RCI1 are vulnerable to CVE-2026-24936.