What is CVE-2026-51367?
This vulnerability in Bottinelli Informatica Vedo Suite version 1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter. Administrators of affected systems should immediately apply the security update provided by the vendor.
Azərbaycanca: Bu boşluq Bottinelli Informatica Vedo Suite 1.2.5 versiyasındakı api_vedo/chat endpoint-ində utente_chat parametri vasitəsilə uzaqdan hücumçuya həssas məlumatları əldə etməyə imkan verir. Təsirlənən sistemlərin administratorları dərhal təchizatçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which version of Bottinelli Informatica Vedo Suite is affected by CVE-2026-51367?
This vulnerability affects Bottinelli Informatica Vedo Suite version 1.2.5.
Through which endpoint and parameter can an attacker exploit CVE-2026-51367 to obtain sensitive information?
An attacker can remotely obtain sensitive information via the `api_vedo/chat` endpoint and the `utente_chat` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.