What is CVE-2026-19356?
A vulnerability in MingSoft MCMS up to version 3.0.6 allows information disclosure via an unknown function in the /mdiy/form/data/list file within the ms-mdiy component. This issue can be exploited remotely and has a publicly available exploit. Updating to the latest version is strongly recommended.
Azərbaycanca: MingSoft MCMS platformasının 3.0.6 versiyasına qədər olan versiyalarında ms-mdiy komponentindəki /mdiy/form/data/list faylında məlumat sızmasına səbəb olan zəiflik aşkarlanıb. Bu boşluq uzaqdan istismar edilə bilər. Təhlükəsizlik tədbiri olaraq MCMS sisteminin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of MingSoft MCMS are affected by CVE-2026-19356?
MingSoft MCMS versions up to 3.0.6 are affected by this vulnerability.
What is the impact of exploiting CVE-2026-19356?
This vulnerability can be exploited remotely and leads to information disclosure via the /mdiy/form/data/list file in the ms-mdiy component.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.