cvedb.io
CVE-2026-35548
HIGH · CVSS 8.5
EPSS exploitation probability: 0%
Published 2026-04-22T15:16:16.100 · Last modified 2026-06-17T10:40:45.710

Summary

An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowed stored database credentials to be reused after modification of the target Host, IP address, or Port. When editing an existing Enrichment Source, previously stored credentials were retained even if the connection endpoint was changed. An authenticated Operator user could redirect the database connection to unintended internal systems, resulting in SSRF and potential misuse of valid stored credentials.

Affected products

guardsix — logpoint

Does this affect you?

Add your gear to cvedb and we'll alert you only when guardsix ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.