8.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Description
An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowed stored database credentials to be reused after modification of the target Host, IP address, or Port. When editing an existing Enrichment Source, previously stored credentials were retained even if the connection endpoint was changed. An authenticated Operator user could redirect the database connection to unintended internal systems, resulting in SSRF and potential misuse of valid stored credentials.
AI Analysis
A logic flaw in guardsix ODBC Enrichment Plugins allows stored database credentials to be reused after modification of the target Host, IP address, or Port, resulting in SSRF and potential misuse of valid stored credentials.
Basic Information
ID
CVE-2026-35548
Source
mitre
Published
Apr 22, 2026 at 00:00
Modified
Apr 22, 2026 at 15:21
Affected Product
Vendor
guardsix
Product
ODBC Enrichment Plugins
Version
before 5.2.1
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
guardsix
Product
ODBC Enrichment Plugins
Version
before 5.2.1