CVE-2026-4312Disclosure(dragonsoft / gcb\/fcb_government_financial_cybersecurity_configuration_audit_software)

LOWCVSS 9.3 · CRITICAL

Signal is active with 9 mentions in latest observed window

Immediate actions

  • Patch dragonsoft gcb\/fcb_government_financial_cybersecurity_configuration_audit_software systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gcb\/fcb_government_financial_cybersecurity_configuration_audit_software

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • 9 total mentions across 1 day

Affected systems

Vendors
Products
gcb\/fcb_government_financial_cybersecurity_configuration_audit_software

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 1d
02579Mentions · 2026-03-17: 9Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-17: 703-17
Signal classification3 categories
Disclosure
666.7%
General
222.2%
Patch
111.1%
Referenced assets8 URLs
Full discourse9 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4312: DrangSoft|GCB/FC... Admin account creation via unauthenticated API calls - audit software that can't audit its own access controls. #AuthBypass #CriticalRCE. https://zerodaysignal.com/vulnerability/CVE-2026-4312 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a new critical remote code execution vulnerability (CVE‑2026‑4312) in DrangSoft, where unauthenticated API calls can create admin accounts.

    10020131
    152 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4312 - Critical GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administ... https://www.thehackerwire.com/vulnerability/CVE-2026-4312/ https://t.co/YW6igrhlwe

    Post summary

    The post announces a critical missing‑authentication flaw in DrangSoft’s GCB/FCB Audit Software, detailing the vulnerability type but providing no PoC, patch, or exploitation evidence.

    0001062
    138 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4312 Missing Authentication Vulnerability in DrangSoft GCB/FCB Audit Software Enabling Admin Account Creation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4312

    Post summary

    The text identifies a missing authentication vulnerability in DrangSoft GCB/FCB Audit Software that permits admin account creation, but offers no further technical, exploit, or mitigation details.

    0001065
    4.0K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4312 — CVSS 9.8/10 ██████████ GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Q5BR3xRTFU

    Post summary

    The tweet flags a critical missing authentication flaw in DrangSoft's GCB/FCB Audit Software, advises applying the patch immediately, and highlights a CVSS score of 9.8.

    1000036
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4312 GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to c… https://www.cve.org/CVERecord?id=CVE-2026-4312

    Post summary

    CVE‑2026‑4312 is a missing‑authentication flaw in DrangSoft's GCB/FCB Audit Software permitting unauthenticated remote attackers to access specific APIs.

    00000153
    56.7K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4312 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4312 #CVE-2026-4312 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/48khgJzFxW

    Post summary

    The tweet announces the new critical CVE-2026-4312 with a severity of 9.8 but does not provide technical details, exploit code, or mitigation information.

    0000049
    101 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4312 - DrangSoft|GCB/FCB Audit Software - Missing Authentication Intel Report: https://ift.tt/3O5QYqg

    Post summary

    A brief alert identifies CVE-2026-4312 as a missing authentication flaw in DrangSoft Audit Software, with an intel report link, but provides no PoC, exploit code, or patch information.

    0000037
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4312 - DrangSoft|GCB/FCB Audit Software - Missing Authentication Intel Report: https://ift.tt/3rpTNGW

    Post summary

    The alert announces CVE‑2026‑4312, a missing authentication flaw in DrangSoft GCB/FCB Audit Software, and references an Intel report.

    0000043
    336 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4312: CRITICAL] DrangSoft's GCB/FCB Audit Software has a critical Missing Authentication vulnerability, enabling remote attackers to create admin accounts. #CyberSecurity#cve,CVE-2026-4312,#cybersecurity https://cvefind.com/CVE-2026-4312

    Post summary

    The post discloses a critical missing authentication flaw in DrangSoft's GCB/FCB Audit Software that enables remote creation of admin accounts, with no PoC, exploit, or mitigation detailed.

    0000079
    602 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdragonsoftgcb\/fcb_government_financial_cybersecurity_configuration_audit_software---

Explore more