---
id: CVE-2026-19358
title: A weakness has been identified in 3CORESec Trapdoor up to 1.2.2
summary: >-
  A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by
  this vulnerability is the function DefaultFunction. This manipulation causes
  improper access controls. The attack can be initiated remotely. The vendor was
  cont…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-284
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19358'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-19358'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/866021'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387212'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387212/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-10T00:37:58.085Z'
epss: 0.00347
epssPercentile: 0.25522
---

## Overview

A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
