CVE-2026-82486: SiteServer SSCMS Agent Installation Workflow access control
A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Does an attacker need an authenticated account to exploit this issue?
The vector indicates no privileges are required, but exploitation requires user interaction. The attack is remote and is described as high complexity and difficult to exploit.
Which systems should be assessed for exposure?
Assess deployments running SiteServer SSCMS 7.4.0, particularly where the Agent Installation Workflow is available. The available information does not identify the full scope of affected functionality within that component.
Is a vendor fix or workaround identified?
No fix or workaround is identified in the provided information. The project was notified through an issue report but had not responded at the time of publication.