轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202603-00000011
[內容說明]
【葳橋資訊|單一簽入暨電子目錄服務系統 - Local File Inclusion】(CVE-2026-3826,CVSS:9.8) 未經身分鑑別之遠端攻擊者可利用此漏洞於伺服器端執行任意程式碼。
[影響平台]
單一簽入暨電子目錄服務系統 IFTOP_P4_181(不含)以前版本
[建議措施]
更新至IFTOP_P4_181(含)以後版本
[參考資料]
1. https://www.twcert.org.tw/tw/cp-132-10755-94136-1.html
Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202603-00000011
[Content Description]
【WellChoose Information|Single Sign-in and Electronic Directory Service - Local File Inclusion】(CVE-2026-3826, CVSS: 9.8) An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the server.
[Affected Platforms]
Single Sign-in and Electronic Directory Service versions prior to IFTOP_P4_181 (excluding IFTOP_P4_181)
[Recommended Actions]
Update to IFTOP_P4_181 (including IFTOP_P4_181) or later
[References]
1. https://www.twcert.org.tw/tw/cp-132-10755-94136-1.html