What is CVE-2026-57262?
LOGO! Soft Comfort uses a static, hardcoded AES master key to encrypt project files. This vulnerability allows a local attacker to extract the key from application files or memory and decrypt project files. All software versions below V9 are affected and should be updated immediately.
Azərbaycanca: LOGO! Soft Comfort proqramında layihə fayllarını şifrələmək üçün statik, sabit kodlu AES açarı istifadə edilir. Bu zəiflik yerli təcavüzkara proqram fayllarından və ya yaddaşdan açarı çıxarıb layihə fayllarını deşifrə etməyə imkan verir. Məhsulun V9-dan aşağı bütün versiyaları təsirlənir və dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
What causes the CVE-2026-57262 vulnerability related to project file encryption in LOGO! Soft Comfort?
The vulnerability stems from the use of a static, hardcoded AES key to encrypt project files.
Which versions of LOGO! Soft Comfort need to be updated to protect against CVE-2026-57262?
All software versions below V9 are affected and should be updated immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.