VORANT. Threat Intelligence Sign in Get the full feed

STER software patches three vulnerabilities

medium vulnerability

STER software had a SQL injection, weak password encoding, and unencrypted TCP traffic flaws, all fixed in version 9.5.

CERT Polska coordinated disclosure of three vulnerabilities in STER software, reported by Michelin CERT. CVE-2026-25606 is a SQL injection vulnerability in the application's Search Filters that allows an authenticated attacker to access sensitive data belonging to other users or any data the application can reach. CVE-2026-25607 involves use of a weak password encoding algorithm, which could allow an attacker to derive password values by analyzing how known passwords are encoded. CVE-2026-25608 stems from STER's use of unencrypted TCP traffic to transmit data, exposing passwords, personal data, and authentication tokens to Man-in-the-Middle attacks.

All three issues were addressed in STER version 9.5. There is no indication in the advisory of active exploitation in the wild; this is a standard responsible disclosure and patch notice rather than evidence of an ongoing attack campaign.

Mentioned in this report

Vulnerabilities CVE-2026-25606CVE-2026-25607CVE-2026-25608

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-25606

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free