Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, thereby escalating privileges.
Advisories

No advisories yet.

Fixes

Solution

Contact the vendor to obtain the patch.


Workaround

No workaround given by the vendor.

History

Tue, 24 Mar 2026 05:15:00 +0000

Type Values Removed Values Added
Description Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, thereby escalating privileges.
Title Galaxy Software Services|Vitals ESP - Incorrect Authorization
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-03-24T04:17:47.683Z

Reserved: 2026-03-23T10:47:13.571Z

Link: CVE-2026-4639

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-24T05:16:25.167

Modified: 2026-03-24T05:16:25.167

Link: CVE-2026-4639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses