CVE-2026-80234: CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication
CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CAYIN CMS-SEto a version that resolves this vulnerability.Fixed in 11.0.26198 - Upgrade
Upgrade
CAYIN CMS-WSto a version that resolves this vulnerability.Fixed in 1.0.26198
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker can exploit the affected functionality remotely without authentication. No privileges or user interaction are required.
What information can be exposed?
The vulnerability allows an unauthenticated attacker to obtain media file lists. The reported impact is partial information disclosure; no integrity or availability impact is described.
Which deployments are affected?
The issue affects CAYIN CMS-WS and CAYIN CMS-SE. The available information does not identify affected versions, configuration prerequisites, or a workaround.