CVE-2026-40118 PUBLISHED

Assigner: jpcert
Reserved: 09.04.2026 Published: 16.04.2026 Updated: 16.04.2026

UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor Arcserve
Product UDP Console
Versions
  • Version 10.3 is affected

References

Problem Types