What is CVE-2026-5426?
This is a ViewState deserialization vulnerability in the KnowledgeDeliver Learning Management System by Digital Knowledge. An attacker can achieve remote code execution by sending a crafted ViewState to the compromised server. Immediate patching of affected systems is strongly advised.
Azərbaycanca: Bu zəiflik Yaponiyada geniş istifadə olunan KnowledgeDeliver LMS platformasının ViewState deserializasiya mexanizmində aşkarlanıb. Təcavüzkar serverə xüsusi hazırlanmış ViewState göndərərək uzaqdan kod icrasına nail ola bilər. Təsirlənən sistemlərin dərhal yamalanması tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which platform is affected by CVE-2026-5426?
This vulnerability affects the KnowledgeDeliver LMS platform, which is widely used in Japan.
How can an attacker achieve Remote Code Execution (RCE) via CVE-2026-5426?
An attacker can achieve remote code execution by sending a crafted ViewState to the server, exploiting the ViewState deserialization mechanism.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.