216.73.217.22

CVE-2026-5426

· Published 16/04/2026 18:16 · Modified 26/05/2026 21:28 · Author: The MITRE Corporation

Labels: CVE-2026-5426 2026-04-16CVE-2026-5426CWE-321[email protected]

Essential information

Published
16/04/2026 18:16
Modified
26/05/2026 21:28
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CWE-321
EPSS (First)
P15.4% ?EPSS percentile: rank of this vulnerability versus all others. Higher percentile = more likely to be exploited. Learn more (score 0.00050)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
digital knowledge / knowledgedeliver cpe:2.3:a:digital_knowledge:knowledgedeliver:*:*:*:*:*:*:*:*
aspnet / asp.net cpe:2.3:a:aspnet:asp.net:*:*:*:*:*:*:*:*

References