CVE-2026-40204
Deferred Deferred - Pending Action

Remote Code Execution in Open-Xchange App Suite

Vulnerability report for CVE-2026-40204, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: Open-Xchange

Description

None None None No publicly available exploits are known.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-18
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability has a CVSS v3.1 base score of 3.1, indicating low severity. It requires low privileges and has no user interaction requirement. The attack vector is network-based, and it may allow unauthorized modification of data (integrity impact labeled as low). No known public exploits exist for this issue.

Detection Guidance

No specific detection methods or commands are provided for this CVE. The vulnerability has no known public exploits and limited details available.

Impact Analysis

The impact is limited due to the low CVSS score. An attacker with low privileges could potentially alter some data without authorization, but the overall risk is minimal. No significant disruption or data loss is expected.

Compliance Impact

The provided CVE data does not specify how this vulnerability impacts compliance with standards like GDPR or HIPAA. The vulnerability has a low CVSS score (3.1) and no known exploits, suggesting limited impact on compliance requirements.

Mitigation Strategies

Since no exploits are known and CVSS score is low (3.1), focus on monitoring for unusual activity. Apply vendor patches if available. Limit user privileges to reduce potential impact.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40204. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart