Sceawere

Vulnerability Detail

CVE-2026-41562UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Norvis Backup Data Exposure

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
16h ago
Vendor
norvisgabriel
Product
Norvis Backup
Attack Type
CWE-201 Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-06T09:17:54.023Z",
  "pubdate": "2026-10-06T09:17:54.023Z",
  "executiveSummary": "A critical security vulnerability has been identified in Norvis Backup software, specifically affecting versions 1.1.0 and prior. This vulnerability is classified as Unauthenticated Sensitive Data Exposure, arising from a lack of proper access control mechanisms on sensitive directories and backup storage endpoints. An unauthenticated, remote attacker can exploit this weakness to access, download, and read sensitive backup archives and system configuration files without requiring any valid credentials or privileges.\nThe risk implication of this vulnerability is severe, as backups frequently contain highly sensitive information, including database dumps, proprietary source code, personally identifiable information (PII), and cryptographic keys. Successful exploitation allows attackers to compromise the confidentiality of the entire organization's data assets managed by the backup system. Furthermore, exposed configuration files may contain administrative credentials, enabling attackers to escalate privileges and establish a persistent foothold within the network.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper implementation of authorization controls within the web-facing administrative interface of Norvis Backup versions <= 1.1.0. Specifically, the application's routing engine and web server configuration fail to restrict access to directories containing backup archives, transaction logs, and system configuration files. Consequently, these sensitive resources are mapped directly to publicly reachable Uniform Resource Identifiers (URIs), allowing direct external access. The application relies on 'security through obscurity' rather than enforcing robust authentication middleware on these endpoints.\nThe attack flow begins with external reconnaissance. An attacker can scan public IP ranges or internal networks to identify active deployments of Norvis Backup, often utilizing signature-based detection, specific HTTP response headers, or default port configurations. Once a target system is identified, the attacker attempts to locate backup archives. Because the application uses predictable naming conventions for backup files (such as timestamps or incremental IDs) or fails to disable directory listing, the attacker can easily determine the exact URLs of the stored backups.\nNext, the attacker issues standard HTTP or HTTPS GET requests targeting the discovered file paths. Because the underlying web server or application framework does not intercept these requests to validate session cookies, JSON Web Tokens (JWTs), or API keys, the request bypasses the authentication perimeter entirely. The server processes the request as an anonymous static file delivery, streaming the backup archive directly to the attacker.\nThe post-exploitation impact of this exposure is critical. Backup files routinely aggregate the most sensitive assets of an organization, including user databases, source code repositories, intellectual property, and system configuration profiles. By extracting the retrieved archive, the attacker gains offline access to this data, completely bypassing any active database firewalls or intrusion detection systems. Furthermore, config files within the backup may reveal database passwords, API keys, or LDAP integration credentials, enabling the attacker to perform lateral movement, compromise connected systems, and escalate privileges to achieve full network infrastructure compromise."
}
CVE-2026-41562: Norvis Backup Data Exposure (HIGH Severity, CVSS: 7.5) | Sceawere