CVE-2026-92555 is a critical (CVSS 9.1) flaw in AKINSOFT WOLVOX Control Panel: the product puts sensitive information into data it sends, and an unauthenticated remote attacker can use this to pull data from system resources.
What Is It
CVE-2026-92555 is classified as CWE-201: Insertion of Sensitive Information Into Sent Data. It affects AKINSOFT WOLVOX Control Panel, made by AKIN Software Computer Import-Export Industry and Trade Co. Ltd. The vulnerability description says the flaw "allows Pull Data from System Resources," which means an attacker can extract data the product should not disclose.
The CVE was published on October 8, 2026. It was reported by USOM, Turkey's national CERT, and NVD lists its status as "Received," so NVD has not yet analyzed it.
Why It Matters
USOM rates the flaw 9.1 (Critical) with this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. In practice, that means:
- Attack vector: Network (remotely reachable)
- Attack complexity: Low
- Privileges required: None
- User interaction: None
- Impact: High confidentiality and high integrity impact; no availability impact
An attacker with network access to the product does not need credentials or help from a user. The high integrity score suggests the exposed data could enable more than read-only access, for example if credentials or session material leak. The supplied data does not say exactly what information is exposed.
Exploitation status: No CISA Known Exploited Vulnerabilities (KEV) entry was found for this CVE, so CISA has not confirmed active exploitation. That can change, but the network reach, low complexity and lack of authentication make this a high-priority fix.
What's Vulnerable
- Vendor: AKIN Software Computer Import-Export Industry and Trade Co. Ltd.
- Product: AKINSOFT WOLVOX Control Panel
- Affected versions: 26.02.25 up to, but not including, 26.02.26
All other versions are listed as unaffected. NVD has not published any CPE identifiers yet.
Patch Status
The affected range ends just before version 26.02.26, so that release appears to contain the fix. Organizations running AKINSOFT WOLVOX Control Panel 26.02.25 should upgrade to 26.02.26 or later and check the USOM advisory below for vendor guidance.
CISA has not issued a required action because the CVE is not in the KEV catalog. Until patched systems are confirmed, consider limiting network access to the Control Panel.