go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Galaxy Software Services|Vitals ESP - 2 Vulnerabilities

TVN ID TVN-202603007
CVE ID CVE-2026-4639, CVE-2026-4640
CVSS CVE-2026-4639:
8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2026-4640:
7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products Vitals ESP version 6.3 and earlier
Description CVE-2026-4639(Incorrect Authorization):
Authenticated remote attackers can perform certain administrative functions, thereby escalating privileges.

CVE-2026-4640(Missing Authentication):
Unauthenticated remote attackers can execute certain functions to obtain sensitive information.
Solution Contact the vendor to obtain the patch.
Credit Huding(DEVCORE)
Public Date 2026-03-23
Top