Cyber Posture

CVE-2026-39907

CriticalPublic PoCUpdated

Published: 14 April 2026

Published
14 April 2026
Modified
06 May 2026
KEV Added
Patch
CVSS Score 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0077 73.7th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-39907 is a critical-severity External Control of File Name or Path (CWE-73) vulnerability in Unisys Webperfect Image Suite. Its CVSS base score is 10.0 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 26.3% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique.
Threat & Defense Details

Likely Mitigating ControlsAI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-73

Rejects externally supplied file or resource identifiers that fail validity checks.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1187 Forced Authentication Credential Access
Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.
Why these techniques?

Unauthenticated public WCF endpoint (T1190) accepts unsanitized UNC paths that force outbound SMB authentication (T1187), leaking NTLM hashes.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak NTLMv2 machine-account…

more

hashes. Attackers can submit crafted SOAP requests with UNC paths to force the server to initiate outbound SMB connections, exposing authentication credentials that may be relayed for privilege escalation or lateral movement within the network.

Deeper analysisAI

Automated synthesis unavailable for this CVE.

Details

CWE(s)

Affected Products

unisys
webperfect image suite
3.0.3960.22604, 3.0.3960.22810

CVEs Like This One

CVE-2026-39906Same product: Unisys Webperfect Image Suite
CVE-2025-65115Shared CWE-73
CVE-2025-10134Shared CWE-73
CVE-2025-65473Shared CWE-73
CVE-2026-30281Shared CWE-73
CVE-2024-22341Shared CWE-73
CVE-2026-5809Shared CWE-73
CVE-2025-12529Shared CWE-73
CVE-2025-5393Shared CWE-73
CVE-2025-58762Shared CWE-73

References