Description
2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation. This vulnerability can only be exploited after authenticating with administrator privileges.
References (1)
Core 1
Core References
Various Sources vendor-advisory
https://www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf
Scores
CVSS v3
7.2
EPSS
0.0029
EPSS Percentile
20.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-117
Status
published
Products (1)
2n/access_commander
< 3.4.2
Published
Mar 04, 2026
Tracked Since
Mar 04, 2026