CVE-2026-101083
Received Received - Intake

Information Disclosure in PMWeb via EncryptionHelper DLL

Vulnerability report for CVE-2026-101083, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security vulnerability has been detected in PMWeb v7.x/v8.x/v2025.x. Impacted is an unknown function in the library encryptionhelper.dll. Such manipulation leads to information disclosure. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pmweb pmweb From 2025.x (inc) to 8.x (inc)
pmweb pmweb From 7.x (inc) to 9.x (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure issue in PMWeb versions 7.x, 8.x, and 2025.x. It exists in the encryptionhelper.dll library where an unknown function can be manipulated to expose sensitive data. The attack can be executed remotely without requiring user interaction.

Detection Guidance

Detection methods for this vulnerability are not specified in the provided CVE data. The vulnerability involves PMWeb versions v7.x/v8.x/v2025.x and an unknown function in encryptionhelper.dll, but no detection commands or techniques are provided.

Impact Analysis

This vulnerability may allow attackers to remotely access and disclose confidential information from affected PMWeb systems. Since the vendor did not respond to disclosure attempts, there is no official patch, leaving systems exposed to potential data breaches.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other privacy regulations due to unauthorized data exposure. Organizations using affected PMWeb versions may face legal penalties, reputational damage, and mandatory breach notifications.

Mitigation Strategies

Immediate steps include isolating affected systems, applying vendor patches if available, monitoring network traffic for unusual activity, and disabling the encryptionhelper.dll library if exploitation is suspected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101083. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart