CRITICAL🇵🇱 Wersja polska

CVE-2026-6886

CVSS 9.3v4.0pub. 2026-04-23upd. 2026-05-19

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.

🤖 AI Analysis
How it works

The vulnerability, classified as CWE-1390 (Weak Authentication), results from improper implementation of the authentication mechanism in Borg SPM 2007. A remote attacker, without any prior authentication, can bypass the identity verification procedure and gain access to the system with privileges of any chosen user account. No user interaction or special environmental conditions are required to conduct the attack.

Impact

An attacker can take full control of user accounts in the system, including accounts with elevated privileges, leading to violations of confidentiality, integrity, and availability of data processed by the application.

Mitigation & patch

The product is discontinued and likely no longer supported by the vendor. Apply patches available from the vendor according to references (TWCERT). It is strongly recommended to immediately discontinue the product and replace it with a currently supported solution. Until migration is complete, isolate the system from public networks using firewalls or other network access control mechanisms.

Who is affected

Borg SPM 2007 produced by BorG Technology Corporation (product discontinued from sales in 2008)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References