CVE-2026-40551
Use of Client-Side Authentication in mpGabinet
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 and below.
| CWE | CWE-603 |
| Vendor | binsoft |
| Product | mpgabinet |
| Published | Apr 28, 2026 |
| Last Updated | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for binsoft mpgabinet
Be the first to know when new unknown vulnerabilities affecting binsoft mpgabinet are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
BinSoft / mpGabinet
0 โค 23.12.19
References
Credits
Robert Kruczek Kamil Szczurowski