← Vulnerability feed

Vulnerability record · CVE-2022-26971 · published 2 June 2022

CVE-2022-26971: Barco control room management suite missing authentication for critical function vulnerability

BBarco · Control Room Management Suite

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.

5.3 CVSS 3.1 Medium EPSS 0.71% · top 48.4% CWE-306 · Missing authentication for critical function
5.3CVSS 3.1 base score, v2 5.0
0.71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26971 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2022-26975Barco control room management suite improper authentication vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.EPSS 0.99%7.5CVE-2022-26233Barco control room management suite path traversal vulnerabilityBarco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensi…EPSS 15%6.1CVE-2022-26974Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input san…EPSS 0.55%6.1CVE-2022-26977Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of i…EPSS 0.55%6.1CVE-2022-26978Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_use…EPSS 0.55%6.1CVE-2022-26972Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameter…EPSS 0.55%5.4CVE-2022-26976Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of i…EPSS 0.44%5.3CVE-2022-26973Barco control room management suite error message information leak vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaki…EPSS 0.75%

Source: NIST National Vulnerability Database (record CVE-2022-26971), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.