CVE-2026-39907Disclosure(unisys / webperfect_image_suite)

LOWCVSS 10.0 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak NTLMv2 machine-account hashes. Attackers can submit crafted SOAP requests with UNC paths to force the server to initiate outbound SMB connections, exposing authentication credentials that may be relayed for privilege escalation or lateral movement within the network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webperfect_image_suite

Threat summary

  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked at 5 mentions on most recent observed day (2026-05-12)
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
webperfect_image_suite

2 versions affected across 1 product

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-04-15: 2Mentions · 2026-05-12: 5Technical Details · 2026-04-15: 2Technical Details · 2026-05-12: 404-1505-12
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure2
2026-05-125
Disclosure4General1
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CRITICAL: CVE-2026-39907 (CVSS 10) — unisys webperfect image suite

    Post summary

    A new critical vulnerability with CVSS 10 (CVE-2026-39907) affecting Unisys WebPerfect Image Suite has been announced.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 10 CRITICAL · CVE-2026-39907 · 3.0.3960.22810 → 3.0.3960.22604 CRITICAL: CVE-2026-39907 (CVSS 10) — unisys webperfect image suite

    Post summary

    The text announces a critical vulnerability (CVE‑2026‑39907) affecting Unisys WebPerfect Image Suite, listing its CVSS score and affected version ranges, but provides no proof of exploitation or mitigation advice.

    1000037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-39907 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory CRITICAL: CVE-2026-39907 (CVSS 10) — unisys webperfect image suite

    Post summary

    A new critical vulnerability (CVE‑2026‑39907) for Unisys WebPerfect Image Suite has been disclosed, boasting a CVSS‑3.1 score of 10 and a critical severity rating.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-39907 (CVSS 10) — unisys webperfect image suite Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName…

    Post summary

    A critical vulnerability (CVSS 10) in Unisys WebPerfect Image Suite is disclosed, describing an unauthenticated SOAP endpoint that accepts unsanitized file paths.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-39907-unisys-webperfect-image-suite #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The snippet merely links to a research article and includes generic hashtags, providing no substantive details about the CVE, its exploitation status, or remediation.

    0000023
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39907 Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file pa… https://www.cve.org/CVERecord?id=CVE-2026-39907

    Post summary

    CVE-2026-39907 discloses an unauthenticated WCF SOAP endpoint on Unisys WebPerfect Image Suite that accepts unsanitized file parts, indicating a potential remote exploitation vector.

    0000089
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39907 Unauthenticated NTLMv2 Hash Leakage via WCF SOAP Endpoint in Unisys WebPerfect Image Suite https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39907

    Post summary

    The post announces CVE‑2026‑39907, detailing unauthenticated NTLMv2 hash leakage through a WCF SOAP endpoint in Unisys WebPerfect Image Suite, with no mention of PoC, exploit tools, or active exploitation.

    0000057
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appunisyswebperfect_image_suite3.0.3960.22604--
Appunisyswebperfect_image_suite3.0.3960.22810--

Explore more