๐Ÿ” CVE Alert

CVE-2026-19061

LOW 3.7

Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList data authenticity

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-345
Vendor insta
Product instaknxserviceapp
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for insta instaknxserviceapp

Be the first to know when new low vulnerabilities affecting insta instaknxserviceapp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Insta / InstaKNXServiceApp
1.2.3.1469

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/386531 vuldb.com: https://vuldb.com/vuln/386531/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19061 vuldb.com: https://vuldb.com/submit/864343 gist.github.com: https://gist.github.com/isZzzz/f9da7d76cf2f7b93ec3f90efe17ed323

Credits

๐Ÿ” isZzzzz (VulDB User) VulDB CNA Team