ZDI-CAN-28597: ZDI-26-077: GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MArc.Store.Remoting.exe process, which listens on port 8018. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-2039.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28597?
ZDI-CAN-28597 is considered a critical vulnerability due to the ease of exploitation and its potential impact on sensitive data.
How do I fix ZDI-CAN-28597?
To fix ZDI-CAN-28597, users should apply the latest security updates provided by GFI for the Archiver software.
Who is affected by ZDI-CAN-28597?
ZDI-CAN-28597 affects installations of GFI Archiver that have not been updated to the latest security version.
What are the potential consequences of exploiting ZDI-CAN-28597?
Exploiting ZDI-CAN-28597 could allow attackers to access sensitive information without proper authentication.
Is authentication required to exploit ZDI-CAN-28597?
No, authentication is not required to exploit ZDI-CAN-28597, making it particularly dangerous.