Skip to content
Threat Feed
critical advisory PoC updated

Information Disclosure Vulnerability in AKINSOFT WOLVOX Control Panel

CVE-2026-92555 allows for the unauthorized extraction of sensitive information via the 'Pull Data from System Resources' function in AKINSOFT WOLVOX Control Panel versions 26.02.25.

CVE search metadata

CVE search record: CVE-2026-92555. Severity: critical. CVSS: 9.8. KEV: no. Product: WOLVOX Control Panel (26.02.25). Brief: Information Disclosure Vulnerability in AKINSOFT WOLVOX Control Panel. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92555/

What's new

  • 1. poc_available Oct 8, 19:25 via sploitus

CVE-2026-92555 is a high-severity information disclosure vulnerability identified in the AKINSOFT WOLVOX Control Panel, specifically within the 'Pull Data from System Resources' functionality. This flaw occurs when the application fails to properly secure data retrieved from internal system resources, resulting in sensitive information being included in outgoing data transmissions. An attacker capable of triggering this function can intercept or access sensitive system details that should remain protected. This vulnerability affects WOLVOX Control Panel versions starting from 26.02.25 and is resolved in version 26.02.26. Given the sensitive nature of the information processed by control panels of this type, successful exploitation risks significant data exposure of internal system configurations and operational parameters.

Impact

The vulnerability poses a severe risk to organizational confidentiality by allowing unauthorized access to internal system resources. If successfully exploited, attackers can exfiltrate sensitive data transmitted by the application, potentially leading to further reconnaissance or compromise of the environment where WOLVOX is deployed.

Recommendation

Update the AKINSOFT WOLVOX Control Panel to version 26.02.26 or later immediately to patch CVE-2026-92555. Organizations should restrict network access to the control panel interface to trusted management networks only to minimize the risk of unauthorized data requests.

Mitigations

Upgrade AKINSOFT WOLVOX Control Panel to 26.02.26 or later.

immediate IT Operations

CVE-2026-92555