Sceawere
Vulnerability Detail
CVE-2026-92555UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AKINSOFT WOLVOX Information Exposure Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 2h ago
- Vendor
- AKIN Software Computer Import-Export Industry…
- Product
- AKINSOFT WOLVOX Control Panel
- Attack Type
- CWE-201 Insertion of sensitive information into sent data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources. This issue affects AKINSOFT WOLVOX Control Panel: from 26.02.25 before 26.02.26.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-08T12:17:18.787Z",
"pubdate": "2026-10-08T12:17:18.787Z",
"executiveSummary": "This vulnerability involves the improper insertion of sensitive information into transmitted data within the AKINSOFT WOLVOX Control Panel.\nThe issue is classified as an information exposure vulnerability, specifically affecting the 'Pull Data from System Resources' functionality.\nAffected versions range from 26.02.25 to, but not including, 26.02.26.\nThe vulnerability allows unauthorized or unintended disclosure of sensitive data that is processed or handled by the system's resource pulling mechanism.\nSuccessful exploitation could lead to the exposure of confidential information to unauthorized entities, potentially compromising system integrity and data privacy.\nAttackers capable of triggering the affected system function may be able to intercept or retrieve sensitive details that should otherwise be protected or scrubbed before transmission.\nThe risk implication is significant as it facilitates potential data exfiltration or reconnaissance within the environment where the WOLVOX Control Panel is deployed.",
"technicalDetails": "The vulnerability resides within the 'Pull Data from System Resources' mechanism of the AKINSOFT WOLVOX Control Panel.\nThe root cause is an insecure handling of sensitive data during the data extraction and transmission process, where information that should be sanitized or excluded is incorrectly included in the payload sent by the system.\nThis indicates a failure in the application's output filtering or data masking controls during the internal processes triggered by the 'Pull Data' function.\nThe attack flow typically involves an actor triggering the 'Pull Data from System Resources' operation. When this function is invoked, the application retrieves system-level resources or configuration data. Due to inadequate sanitization logic, sensitive, non-public, or internal parameters are appended to the outgoing data stream without encryption or masking.\nThe vulnerable component is the data processing module responsible for communicating system resource states to the user interface or external endpoints.\nExploitation requires access to the WOLVOX Control Panel's interface or API endpoints that expose the 'Pull Data' functionality. Depending on the architecture, this may require authenticated access, though the vulnerability's impact remains critical if the information leaked provides credentials, system keys, or infrastructure topology.\nUpon exploitation, the attacker receives a response containing the sensitive data intended for internal system use. This payload may contain environment variables, internal file paths, or cached credentials that were incorrectly included in the transmission.\nPost-exploitation, an attacker can leverage this sensitive information to conduct lateral movement, elevate privileges, or perform further attacks against the underlying infrastructure that the WOLVOX Control Panel manages.\nBecause the vulnerability occurs at the intersection of resource management and data reporting, the exposure is persistent as long as the 'Pull Data' function is executed on the affected software versions (26.02.25 through 26.02.25.x).\nTechnical mitigations require the implementation of strict data filtering rules to ensure that only authorized and necessary data fields are included in the 'Pull Data' response objects, effectively white-listing the allowed information rather than relying on black-listing or lack of sanitization."
}