CVE-2026-82989: Critical severity ViewSonic ViewBoard vulnerability
Published Oct 5, 2026
·Updated
There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints
Affected Software
1 affected component
ViewSonic ViewBoard
Event History
Oct 5, 2026
CVE Published
via MITRE·11:14 PM
Data Sourced
via MITRE·11:14 PM
DescriptionWeakness
Oct 6, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
ViewSonic ViewBoard deployments with vCast exposed network services are affected. The issue is reachable through network-based HTTP requests to unauthenticated service endpoints.
2
What does an attacker need to exploit it?
An attacker needs network access to the exposed vCast service endpoints. No authentication is required.
3
What can an attacker do?
A remote attacker can inject arbitrary input into the affected service endpoints.