CVE-2026-5726 is a stack-based buffer overflow vulnerability affecting ASDA-Soft products that allows unauthenticated attackers with local access to execute arbitrary code with high privileges. The vulnerability has a CVSS score of 8.4 (HIGH) and requires no user interaction, making it a significant risk for affected systems. Attack complexity is low, and successful exploitation could result in complete compromise of confidentiality, integrity, and availability. The vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation in the wild, with minimal community attention indicated by its inactive Hot List status. Although the EPSS score is extremely low (0.000050), indicating limited real-world exploitation probability, the high CVSS rating warrants prompt patching of affected ASDA-Soft installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2.6.0CPE matchmatch criteria | cpe:2.3:a:deltaww:asda_soft:*:*:*:*:*:*:*:* | ||
>= 0, <= 7.2.2.0CPE match | cpe:2.3:a:deltaww:asda_soft:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.