CVE-2026-0872 PUBLISHED

Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon

Assigner: THA-PSIRT
Reserved: 13.01.2026 Published: 13.02.2026 Updated: 13.02.2026

Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:P
CVSS Score: 2.5

Product Status

Vendor Thales
Product SafeNet Agent for Windows Logon
Versions Default: unaffected
  • Version 4.0.0 is affected
  • Version 4.1.1 is affected
  • Version 4.1.2 is affected

Solutions

Upgrade to version 4.1.3.

Credits

  • Huy Kha, Director of Security Research, and the team at Netwrix finder

References

Problem Types

  • CWE-295 Improper Certificate Validation CWE

Impacts

  • CAPEC-475 Signature Spoofing by Improper Validation