Cyber & AI intelligence
Wasteland.
Briefs indexed3056
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-92555 2026-10-08

CVE-2026-92555: Critical Data Exposure Flaw in AKINSOFT WOLVOX Control Panel

"CVE-2026-92555 is a critical (CVSS 9.1) flaw in AKINSOFT WOLVOX Control Panel: the product puts sensitive information into data it sends, and an unauthenticated remote attacker can use this to pull data from system…"

CVE-2026-92555 is a critical (CVSS 9.1) flaw in AKINSOFT WOLVOX Control Panel: the product puts sensitive information into data it sends, and an unauthenticated remote attacker can use this to pull data from system resources.

What Is It

CVE-2026-92555 is classified as CWE-201: Insertion of Sensitive Information Into Sent Data. It affects AKINSOFT WOLVOX Control Panel, made by AKIN Software Computer Import-Export Industry and Trade Co. Ltd. The vulnerability description says the flaw "allows Pull Data from System Resources," which means an attacker can extract data the product should not disclose.

The CVE was published on October 8, 2026. It was reported by USOM, Turkey's national CERT, and NVD lists its status as "Received," so NVD has not yet analyzed it.

Why It Matters

USOM rates the flaw 9.1 (Critical) with this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. In practice, that means:

An attacker with network access to the product does not need credentials or help from a user. The high integrity score suggests the exposed data could enable more than read-only access, for example if credentials or session material leak. The supplied data does not say exactly what information is exposed.

Exploitation status: No CISA Known Exploited Vulnerabilities (KEV) entry was found for this CVE, so CISA has not confirmed active exploitation. That can change, but the network reach, low complexity and lack of authentication make this a high-priority fix.

What's Vulnerable

All other versions are listed as unaffected. NVD has not published any CPE identifiers yet.

Patch Status

The affected range ends just before version 26.02.26, so that release appears to contain the fix. Organizations running AKINSOFT WOLVOX Control Panel 26.02.25 should upgrade to 26.02.26 or later and check the USOM advisory below for vendor guidance.

CISA has not issued a required action because the CVE is not in the KEV catalog. Until patched systems are confirmed, consider limiting network access to the Control Panel.

Sources