CVE-2026-8364 PUBLISHED

Gladinet Triofox Missing Authentication for Critical Functions

Assigner: tenable
Reserved: 11.05.2026 Published: 27.05.2026 Updated: 28.05.2026

Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Gladinet
Product Triofox
Versions Default: unaffected
  • affected from 0 to 17.3.10565.57509 (excl.)

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-54 Query System for Information