PT-2026-67002 · Unknown · Eparakstītājs 3.0

CVE-2026-0392

·

Published

2026-08-03

·

Updated

2026-08-05

CVSS v4.0

7.3

High

VectorAV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions eParakstītājs 3.0 for Windows versions prior to 1.10.0
Description The application retrieves and executes automatic updates through a channel that lacks authentication and integrity protection. During launch, the software fetches an XML update descriptor over TLS but employs a permissive TrustManager and a HostnameVerifier that always returns true, effectively accepting any TLS certificate. Additionally, the application fails to verify digital signatures on the update descriptor or check the Authenticode signature and checksum of the downloaded installer before execution. A man-in-the-middle attacker capable of redirecting traffic from www.eparaksts.lv can provide a malicious update descriptor that directs the client to download and execute an attacker-controlled executable, leading to arbitrary code execution on the host.
Recommendations Update eParakstītājs 3.0 for Windows to version 1.10.0 or later.

Fix

RCE

Improper Certificate Validation

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0392

Affected Products

Eparakstītājs 3.0