CVE-2026-26222Disclosure(beyond / altec_doclink)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch beyond altec_doclink systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmarshalling, allowing remote attackers to read arbitrary files from the underlying system by specifying local file paths. Additionally, attackers can coerce SMB authentication via UNC paths and write arbitrary files to server locations. Because writable paths may be web-accessible under IIS, this can result in unauthenticated remote code execution or denial of service through file overwrite.

0.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-502CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • altec_doclink

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
altec_doclink

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-24: 1Mentions · 2026-02-25: 2Mentions · 2026-02-26: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 102-2402-2502-26
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-241
Disclosure1
2026-02-252
Disclosure2
2026-02-261
Disclosure1
Full discourse4 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerability in #Altec DocLink. CVE-2026-26222 CVSS: 10.0. Exploitation can lead to remote code execution #RCE! More info: https://www.vulncheck.com/advisories/doclink-net-remoting-unauthenticated-arbitrary-file-read-write-rce #Patch #Patch #Patch

    Post summary

    A critical CVE-2026-26222 vulnerability in Altec DocLink with CVSS 10.0 enabling remote code execution is disclosed, with a patch referenced.

    00001272
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26222 Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe us… https://www.cve.org/CVERecord?id=CVE-2026-26222

    Post summary

    The CVE details insecure .NET Remoting endpoints in Altec DocLink 4.0.336.0, exposing potential remote code execution via TCP and HTTP/SOAP.

    00000140
    56.6K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-26222 in Altec DocLink 4.0.336.0 allows unauthenticated RCE & data exposure via unsafe deserialization. Immediate isolation & network restrictions advised! 🔒 More: https://radar.offseq.com/threat/cve-2026-26222-cwe-502-deserialization-of-untruste-e414adc9 ... https://t.co/CBUCUrS1nn

    Post summary

    CVE-2026-26222 is a critical vulnerability in Altec DocLink that permits unauthenticated remote code execution and data exposure through unsafe deserialization; immediate isolation and network restrictions are recommended.

    0000073
    270 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26222 Unauthenticated Remote File Read and Write Vulnerability ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26222 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-26222 as an unauthenticated remote file read/write vulnerability, but offers no PoC, exploit, or patch details.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbeyondaltec_doclink4.0.336.0--

Explore more