OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-7395 (CVSS 8.5)

NVD · officialPublished Sep 29, 2026Risk 37/100

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.

CVSS
8.5
AV:NetworkAC:LowPR:NoneUI:Active

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source