CVE Database
/

CVE-2026-4760

Back to search

CVE-2026-4760

Published: Mar 25, 2026

Modified: Mar 26, 2026

PUBLISHED

Description

From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt .

VendorProductVersions

CODRA

Panorama Suite

affected
Panorama Suite 2022-SP1 - < update PS-2210-02-4079
affected
Panorama Suite 2023 - < update PS-2300-03-3078 AND PS-2300-04-3078 AND PS-2300-82-3078
affected
Panorama Suite 2025 - < update PS-2500-02-1078 AND PS-2500-04-1078
affected
Panorama Suite 2025 Updated Dec. 25 - < update PS-2510-02-1077 AND PS-2510-04-1077

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now