BDU:2026-05967
Description
Уязвимость модуля Intec.Core программного комплекса INTEC Universe связана с неверным управлением генерацией кода. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код
In plain language
AI Worth attentionAn issue in Intec.Core (INTEC Universe) can let a remote attacker run arbitrary code without any login; small businesses should act by checking their version and updating the module as soon as possible.
Intec.Core in INTEC Universe has a remote code execution weakness caused by improper control of code generation (CWE-94), enabling unauthenticated network-triggered arbitrary code execution; patch is available by upgrading Intec.Core to 1.2.30+.
What to do now
- Check whether your INTEC Universe installation uses the Intec.Core module and find its current version.
- If Intec.Core is older than 1.2.30, plan an immediate upgrade to INTEC: Intec.Core version 1.2.30 or higher.
- After upgrading, verify the service starts normally and that you can perform your usual workflows.
- Confirm you have a working backup/restore point so you can recover if the upgrade causes issues.
CVSS Vector Breakdown
AV:NAccess VectorAC:LAccess ComplexityC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for BDU:2026-05967 and every CVE in our database. Create a free account — no credit card required.
Create Free Account