CVE-2026-40551 PUBLISHED

Use of Client-Side Authentication in mpGabinet

Assigner: CERT-PL
Reserved: 14.04.2026 Published: 28.04.2026 Updated: 28.04.2026

mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user.

This issue affects mpGabinet version 23.12.19 and below.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor BinSoft
Product mpGabinet
Versions Default: affected
  • affected from 0 to 23.12.19 (incl.)

Affected Configurations

Application has to beĀ authenticated to the backend server prior to the attack

Credits

  • Robert Kruczek finder
  • Kamil Szczurowski finder

References

Problem Types

  • CWE-603: Use of Client-Side Authentication CWE