CVE-2026-4760 is a high-severity file disclosure vulnerability affecting Panorama Web HMI in Panorama Suite versions 2022-SP1, 2023, 2025, and 2025 Updated Dec. 25, unless specific updates are applied. An unauthenticated attacker can remotely gain read access to server files by knowing their paths, provided these files are accessible to the Servin process execution account. Rated 7.7 HIGH on CVSS, this vulnerability has a low attack complexity and a high impact on confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CODRA | Panorama Suite | >= Panorama Suite 2022-SP1, < update PS-2210-02-4079, >= Panorama Suite 2023, < update PS-2300-03-3078 AND PS-2300-04-3078 AND PS-2300-82-3078, >= Panorama Suite 2025, < update PS-2500-02-1078 AND PS-2500-04-1078, >= Panorama Suite 2025 Updated Dec. 25, < update PS-2510-02-1077 AND PS-2510-04-1077CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.