CVE-2026-35081: Arbitrary process termination vulnerability in method ugw-logstop
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the ugw-logstop method or remove/disable its exposure if not required to prevent remote users with user privileges from terminating arbitrary processes.
ugw-logstop method enabled = false - Compensating control
Restrict access to the interface or service exposing ugw-logstop to trusted IPs/networks (firewall/ACL/VPN) and require authentication/authorization controls to prevent remote user access.
- Operational
Audit system and process logs for unexpected or unauthorized process terminations and investigate any suspicious activity; remediate affected systems and restore services as needed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35081?
The severity of CVE-2026-35081 is high with a score of 7.2.
How do I fix CVE-2026-35081?
To fix CVE-2026-35081, ensure you update the Mbs-solutions Universal Gateway Firmware to the latest version that addresses this vulnerability.
What types of attacks can be performed due to CVE-2026-35081?
CVE-2026-35081 allows an attacker with user privileges to terminate arbitrary processes, potentially leading to denial of service.
What software is affected by CVE-2026-35081?
The affected software for CVE-2026-35081 is the Mbs-solutions Universal Gateway Firmware.
What is the cause of CVE-2026-35081?
CVE-2026-35081 is caused by insufficient validation of user-supplied input in the ugw-logstop method.