CVE-2026-8364: Gladinet Triofox Missing Authentication for Critical Functions
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to TCP port 7878 (the GladServerAgentService listener) to trusted hosts/IP ranges using firewall rules, ACLs, or network segmentation to block unauthenticated remote HTTP requests.
- Operational
Stop and disable the Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) until a vendor patch or official fix is available. If the service is required, keep it offline except from trusted management systems and re-enable only after remediation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8364?
CVE-2026-8364 has a critical severity rating of 9.8.
How do I fix CVE-2026-8364?
To mitigate CVE-2026-8364, ensure that access to the Gladinet Triofox Cloud Server Agent is restricted and implement proper authentication mechanisms.
What are the risks associated with CVE-2026-8364?
CVE-2026-8364 poses severe risks including unauthorized access to critical functions and sensitive data exposure.
What software is affected by CVE-2026-8364?
CVE-2026-8364 affects the Gladinet Triofox Cloud Server Agent.
What does CVE-2026-8364 exploit?
CVE-2026-8364 exploits missing authentication for critical functions in the Gladinet Triofox application.