CVE-2026-40118
Received
Received - Intake
Information Disclosure via Misconfigured UDP Console in Arcserve
Publication date: 2026-04-16
Last updated on: 2026-04-16
Assigner: JPCERT/CC
Description
Description
UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| arcserve | udp_console | 10.3 |
| arcserve | udp_console | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-941 | The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor. |