| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2026-7395 | 8.1 | high |
CVE-2026-7395. Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
|
| CVE-2026-11796 | 4.3 | medium |
CVE-2026-11796. Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured.
|