CVE-2026-105324
CVE-2026-105324 is a critical-severity vulnerability with a CVSS 4.0 base score of 9.2. The underlying weakness is classified as CWE-113.
Key facts
- Severity: Critical (CVSS 4.0 base score 9.2)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-113
- Published:
- Last modified:
Description
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
Frequently asked questions
- What is CVE-2026-105324?
- An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
- How severe is CVE-2026-105324?
- CVE-2026-105324 has a CVSS 4.0 base score of 9.2, rated critical severity.
- Is CVE-2026-105324 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-105324?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-105324 published?
- CVE-2026-105324 was published on 2026-10-07.
References
Other CWE-113 (HTTP Response Splitting) vulnerabilities
- CVE-2026-67289 — Critical (CVSS 9.8): FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the…
- CVE-2026-38967 — Critical (CVSS 9.8): CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
- CVE-2026-34520 — Critical (CVSS 9.1): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser…
- CVE-2025-53007 — High (CVSS 8.9): arduino-esp32 provides an Arduino core for the ESP32. Versions prior to 3.3.0-RC1 and 3.2.1 contain a HTTP Response…
- CVE-2026-75419 — High (CVSS 8.8): go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in…
- CVE-2024-52875 — High (CVSS 8.8): An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the…
Browse all CWE-113 (HTTP Response Splitting) vulnerabilities →