info.cryptobox.comrelease notes
https://info.cryptobox.com/doc/v4.40/4.40.en CVE-2026-5794
MEDIUM
Vulnerability in Cryptobox allows an authenticated user to trigger an account lockout
Record summary
CVE-2026-5794 has a selected CVSS score of 4.9 (medium).
Description
A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 28, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CryptoboxBrowse Ercom / CryptoboxDefault status: affected | CVE List | 4.40.175 | unaffected |
| 4.37.237 to < 4.38.0 | unaffected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-5794