<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WOLVOX Control Panel (26.02.25) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wolvox-control-panel-26.02.25/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 12:55:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wolvox-control-panel-26.02.25/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in AKINSOFT WOLVOX Control Panel</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92555/</link><pubDate>Thu, 08 Oct 2026 12:55:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92555/</guid><description>CVE-2026-92555 allows for the unauthorized extraction of sensitive information via the 'Pull Data from System Resources' function in AKINSOFT WOLVOX Control Panel versions 26.02.25.</description><content:encoded><![CDATA[<p>CVE-2026-92555 is a high-severity information disclosure vulnerability identified in the AKINSOFT WOLVOX Control Panel, specifically within the 'Pull Data from System Resources' functionality. This flaw occurs when the application fails to properly secure data retrieved from internal system resources, resulting in sensitive information being included in outgoing data transmissions. An attacker capable of triggering this function can intercept or access sensitive system details that should remain protected. This vulnerability affects WOLVOX Control Panel versions starting from 26.02.25 and is resolved in version 26.02.26. Given the sensitive nature of the information processed by control panels of this type, successful exploitation risks significant data exposure of internal system configurations and operational parameters.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a severe risk to organizational confidentiality by allowing unauthorized access to internal system resources. If successfully exploited, attackers can exfiltrate sensitive data transmitted by the application, potentially leading to further reconnaissance or compromise of the environment where WOLVOX is deployed.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the AKINSOFT WOLVOX Control Panel to version 26.02.26 or later immediately to patch CVE-2026-92555. Organizations should restrict network access to the control panel interface to trusted management networks only to minimize the risk of unauthorized data requests.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>information-disclosure</category></item></channel></rss>