CVE-2026-18187

HIGH

A format string vulnerability was found in the Internal Backup on the ADM

Title source: cna
STIX 2.1

Description

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

References (1)

Core 1
Core References

Scores

CVSS v4 7.1
EPSS 0.0023
EPSS Percentile 13.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-134
Status published
Products (2)
ASUSTOR Inc./ADM 4.1.0 - 4.3.3.RUN1
ASUSTOR Inc./ADM 5.0.0 - 5.1.3.RI81
Published Jul 30, 2026
Tracked Since Jul 30, 2026