CVE 8.5 HIGH

CVE-2026-35548_CVE-2026-35548

8.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Description

An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowed stored database credentials to be reused after modification of the target Host, IP address, or Port. When editing an existing Enrichment Source, previously stored credentials were retained even if the connection endpoint was changed. An authenticated Operator user could redirect the database connection to unintended internal systems, resulting in SSRF and potential misuse of valid stored credentials.

AI Analysis

A logic flaw in guardsix ODBC Enrichment Plugins allows stored database credentials to be reused after modification of the target Host, IP address, or Port, resulting in SSRF and potential misuse of valid stored credentials.

Basic Information

ID CVE-2026-35548
Source mitre
Published Apr 22, 2026 at 00:00
Modified Apr 22, 2026 at 15:21

Affected Product

Vendor guardsix
Product ODBC Enrichment Plugins
Version before 5.2.1
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor guardsix
Product ODBC Enrichment Plugins
Version before 5.2.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.