CVE-2026-5426 is a critical vulnerability affecting Digital Knowledge KnowledgeDeliver deployments released prior to February 24, 2026, stemming from a hard-coded ASP.NET/IIS machineKey value. This configuration flaw enables attackers to bypass ViewState validation protections and execute arbitrary code through malicious ViewState deserialization attacks. The vulnerability presents a high severity profile with a CVSS score of 7.5, characterized by a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and results in high confidentiality impact, though integrity and availability impacts are not present. Currently, there is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and community attention remains minimal as reflected by the low EPSS score of 0.00066. Organizations running affected versions should prioritize patching to the February 24, 2026 release or later, though the immediate exploitation risk appears contained at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Digital Knowledge | KnowledgeDeliver | >= 0, < 20260224CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.