CVE-2026-39907 is a path traversal and credential theft vulnerability affecting Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604. The vulnerability resides in an unauthenticated WCF SOAP endpoint exposed on TCP port 1208, which fails to properly validate file paths in the ReadLicense action's LFName parameter. This flaw allows remote attackers to submit crafted SOAP requests containing UNC paths to trigger forced outbound SMB connections from the vulnerable server. The attack requires network access to port 1208 but no authentication credentials, representing a network-adjacent attack vector with low complexity. By forcing the server to initiate SMB connections to attacker-controlled systems, threat actors can capture NTLMv2 machine-account hashes. These credentials can subsequently be relayed for privilege escalation or lateral movement within the target network, creating significant exposure to the confidentiality and integrity of networked systems. The vulnerability shows limited current exploitation risk with no known active use in the wild and a low EPSS score of 0.0038, placing it below the median threat distribution. The vulnerability is not currently tracked on CISA's Known Exploited Vulnerabilities catalog, and there is no indication of public exploit code availability or elevated community attention. Organizations should prioritize patching only if they operate the affected Unisys products in exposed network positions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.3960.22604CPE matchmatch criteria | cpe:2.3:a:unisys:webperfect_image_suite:3.0.3960.22604:*:*:*:*:*:*:* | ||
3.0.3960.22810CPE matchmatch criteria | cpe:2.3:a:unisys:webperfect_image_suite:3.0.3960.22810:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.