CVE-2026-5426

HIGH

KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey value

Title source: cna

Description

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-321 CWE-502
Status published
Products (1)
Digital Knowledge/KnowledgeDeliver < 20260224
Published Apr 16, 2026
Tracked Since Apr 16, 2026