CVE-2026-42098Disclosure

MEDIUMCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e.g. using a debugger) and log in as any other user or administrator - then it is possible to do every possible change to the repository. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 17.1 and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-603

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1PoC Mentioned / Linked · 2026-05-21: 1Active Exploitation · 2026-05-21: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-21: 105-1905-21
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-191
Disclosure1
2026-05-211
Active Exploitation1
Full discourse2 posts
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: 1 critical, 4 High, all actively exploited vulnerabilities in #Sparx Pro Cloud Server, Enterprise Architect #CVE-2026-42096 #CVE-2026-42097 #CVE-2026-42098 #CVE-2026-42099 #CVE-2026-42100 CVSS: 9.3-7.1 #PoC available #Patch #Patch #Patch

    Post summary

    The post highlights that five high‑severity CVEs in Sparx Pro Cloud Server are actively exploited in the wild, a PoC exists, and patches are available.

    01010224
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42098 Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterpr… https://www.cve.org/CVERecord?id=CVE-2026-42098

    Post summary

    The text announces CVE-2026-42098 as a role-based access control flaw in Sparx Enterprise Architect that allows authenticated attackers to modify actions, but it does not provide PoC, exploit code, or patch information.

    00000136
    57.5K followersView on X

Explore more