CVE-2026-7382 PUBLISHED

Information Disclosure in MeWare Software's PDKS

Assigner: TR-CERT
Reserved: 29.04.2026 Published: 30.04.2026 Updated: 30.04.2026

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation.

This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor MeWare Software Development Inc.
Product PDKS
Versions Default: unaffected
  • affected from V16.20200313 to VMYR_3.5.2025117 (excl.)

Credits

  • Berat AKŞİT finder

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE
  • CWE-359 Exposure of private personal information to an unauthorized actor CWE

Impacts

  • CAPEC-116 Excavation