CVE-2026-19572

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets2 URLs
Full discourse1 post
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CRITICAL AUTH BYPASS IN FLEXERA FLEXNET PUBLISHER LMADMIN (CVE-2026-19572, CVSS 9.3) Revenera (Flexera) has disclosed a critical authentication bypass in lmadmin, the license-server administration component of FlexNet Publisher, the licensing technology built into many enterprise and engineering software products. • CVE-2026-19572: a hardcoded authentication bypass in an lmadmin SOAP handler could let an unauthenticated user obtain a privileged administrator session without valid credentials • CVSS 4.0: 9.3 (Critical); network attack, low complexity, no privileges or user interaction needed • Weakness: CWE-288 (authentication bypass using an alternate path or channel) • Affected: FlexNet Publisher lmadmin 11.19.11 and earlier (Windows, Linux, macOS and Solaris per the CVE record) • Credited to researcher Ryan Wincey (Securifera) via responsible disclosure What to do: • Find every lmadmin instance, including license servers installed alongside third-party software • Upgrade to lmadmin 11.19.11.1, the fixed release named in Revenera's advisory • Keep the lmadmin management interface off the internet and limit it to trusted admin hosts ⚠️ Analyst Note: Neither the advisory nor the CVE record reports in-the-wild exploitation, and the flaw is not in CISA KEV. Because FlexNet licensing ships inside many vendors' products, lmadmin servers are easy to miss in asset inventories. An administrator session on a license server could be used to tamper with licensing configuration or disrupt the applications that depend on it. Sources: https://community.revenera.com/s/article/CVE202619572-FlexNet-Publisher-lmadmin-SOAP-Authentication-Bypass-Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-19572 #DDW #DarkWeb #CyberSecurity #Flexera #FlexNet #CVE #PatchNow

    1312015.7K
    207.3K followersView on X

Explore more