What is CVE-2026-18187?
A format string vulnerability was found in the Internal Backup feature of ADM. Because user-controlled task input is processed through an unsafe format string operation, an authenticated attacker can exploit this to disclose memory information. It is recommended to update ADM to the latest version.
Azərbaycanca: ADM-in Daxili Yedəkləmə funksiyasında format sətri zəifliyi aşkarlanıb. İstifadəçi tərəfindən idarə olunan tapşırıq girişi təhlükəli format sətri əməliyyatında işləndiyi üçün autentifikasiya olunmuş hücumçu yaddaş məlumatlarını oxuya bilər. ADM-i ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Does exploiting CVE-2026-18187 in ADM require authentication?
Yes, this format string vulnerability can only be exploited by an authenticated attacker.
What is the potential impact of CVE-2026-18187?
This vulnerability can allow an attacker to disclose memory information.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.