{"id":"CVE-2026-19358","title":"A weakness has been identified in 3CORESec Trapdoor up to 1.2.2","summary":"A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was cont…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-266","CWE-284"],"published":"2026-08-09","updated":"2026-08-09","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19358","references":[{"url":"https://vuldb.com/cve/CVE-2026-19358","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/866021","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387212","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387212/cti","label":"cna@vuldb.com"}],"tags":["nvd"],"ingestedAt":"2026-08-10T00:37:58.085Z","epss":0.00202,"epssPercentile":0.10371,"slug":"CVE-2026-19358","body":"## Overview\n\nA weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}