7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
Basic Information
ID
CVE-2026-5426
Source
Mandiant
Published
Apr 16, 2026 at 15:18
Modified
Apr 18, 2026 at 02:31
Affected Product
Vendor
Digital Knowledge
Product
KnowledgeDeliver
Affected Versions
Digital Knowledge KnowledgeDeliver 0