PT-2026-67002 · Unknown · Eparakstītājs 3.0
CVE-2026-0392
·
Published
2026-08-03
·
Updated
2026-08-05
CVSS v4.0
7.3
High
| Vector | AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
eParakstītājs 3.0 for Windows versions prior to 1.10.0
Description
The application retrieves and executes automatic updates through a channel that lacks authentication and integrity protection. During launch, the software fetches an XML update descriptor over TLS but employs a permissive
TrustManager and a HostnameVerifier that always returns true, effectively accepting any TLS certificate. Additionally, the application fails to verify digital signatures on the update descriptor or check the Authenticode signature and checksum of the downloaded installer before execution. A man-in-the-middle attacker capable of redirecting traffic from www.eparaksts.lv can provide a malicious update descriptor that directs the client to download and execute an attacker-controlled executable, leading to arbitrary code execution on the host.Recommendations
Update eParakstītājs 3.0 for Windows to version 1.10.0 or later.
Fix
RCE
Improper Certificate Validation
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eparakstītājs 3.0