CVE-2026-7382

MEDIUM

Information Disclosure in MeWare Software's PDKS

Title source: cna
STIX 2.1

Description

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

References (2)

Core 2
Core References
Third Party Advisory government-resource broken-link
https://www.usom.gov.tr/bildirim/tr-26-0141

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 26.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-359
Status published
Products (1)
MeWare Software Development Inc./PDKS V16.20200313 - VMYR_3.5.2025117
Published Apr 30, 2026
Tracked Since Apr 30, 2026