VORANT. Threat Intelligence Sign in Get the full feed

BinSoft mpGabinet RCE via chained authentication bypass

critical vulnerability

Three vulnerabilities in BinSoft mpGabinet enable unauthenticated RCE by chaining excessive database privileges, client-side authentication bypass, and malicious attachment execution.

CERT Polska disclosed three vulnerabilities in BinSoft mpGabinet software affecting version 23.12.19 and earlier. CVE-2026-40550 exposes administrative database credentials in application memory due to excessive privilege assignment. CVE-2026-40551 allows authentication bypass through client-side verification manipulation. CVE-2026-40552 enables remote command execution when an authenticated user modifies attachment paths in the database to reference attacker-controlled network resources.

The critical risk emerges from chaining all three flaws: an unauthenticated attacker can extract database credentials from memory, bypass authentication to access any account, manipulate attachment references in the database, and achieve system-level command execution when a user opens the malicious attachment. The vulnerabilities stem from fundamental design weaknesses including client-side security controls and overprivileged database access.

The disclosure follows responsible coordinated vulnerability reporting by security researchers Robert Kruczek and Kamil Szczurowski. Organizations running affected mpGabinet versions should prioritize patching, as the exploitation chain requires no special privileges and can be executed remotely by unauthenticated attackers.

Mentioned in this report

Vulnerabilities CVE-2026-40550CVE-2026-40551CVE-2026-40552

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-40550

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free