CVE-2026-6886 PUBLISHED

BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass

Assigner: twcert
Reserved: 23.04.2026 Published: 23.04.2026 Updated: 23.04.2026

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor BorG Technology Corporation
Product Borg SPM 2007
Versions Default: unaffected
  • Version 0 is affected

Solutions

Regardless of the current system version, customers with active maintenance contracts are advised to contact the vendor for patching assistance or upgrade to the latest version (SPM2025 SP1 has successfully passed source code security audits).

References

Problem Types

  • CWE-1390 Weak Authentication CWE

Impacts

  • CAPEC-115 Authentication Bypass