{"id":"CVE-2026-19572","title":"A security vulnerability has been identified in FlexNet Publisher lmadmin","summary":"A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator sessi…","severity":"critical","cvss":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-288"],"vendor":"Flexera","product":"FlexNet Publisher","affected":["flexnet_publisher <= 11.19.11"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T04:18:09.053","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19572","references":[{"url":"https://community.revenera.com/s/article/CVE202619572-FlexNet-Publisher-lmadmin-SOAP-Authentication-Bypass-Vulnerability","label":"PSIRT-CNA@flexerasoftware.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-07T04:29:45.641Z","slug":"CVE-2026-19572","body":"## Overview\n\nA security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":51.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}