CVE-2026-20893
Unknown
Unknown - Not Provided
Origin Validation Flaw in Fujitsu AuthConductor Enables SYSTEM Code Execution
Publication date: 2026-01-07
Last updated on: 2026-01-07
Assigner: JPCERT/CC
Description
Description
Origin validation error issue exists in Fujitsu Security Solution AuthConductor Client Basic V2 2.0.25.0 and earlier. If this vulnerability is exploited, an attacker who can log in to the Windows system where the affected product is installed may execute arbitrary code with SYSTEM privilege and/or modify the registry value.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fujitsu | authconductor_client_basic_v2 | to 2.0.25.0 (exc) |
| fujitsu | authconductor_client_basic_v2 | to 2.0.24.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-346 | The product does not properly verify that the source of data or communication is valid. |