SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12962

MEDIUM · CVSS 5.3 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Armoury Crate permits a remote attacker to exploit a permissive cross-domain security policy, potentially allowing them to capture a local user's NTLM hash by tricking the user into visiting a malicious web page. This could lead to unauthorized access to sensitive information and compromise user accounts. Organizations using Armoury Crate should prioritize addressing this issue to mitigate the risk of credential theft.

CVE
CVE-2026-12962
Severity
MEDIUM
CVSS
5.3
EPSS
0.36%

Original NVD Description

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate AppĀ ' section on the ASUS Security Advisory for more information.