← Vulnerability feed

Vulnerability record · CVE-2023-5830 · published 27 October 2023

CVE-2023-5830: ColumbiaSoft Document Locator WebTools login improper authentication

Documentlocator · Document Locator

CVE-2023-5830 is a critical improper authentication flaw (CWE-287) in ColumbiaSoft Document Locator's WebTools component, specifically the /api/authentication/login endpoint. Manipulating the Server argument allows an attacker to bypass authentication. The vendor addressed it in version 7.2 SP4 and 2021.1.

9.8 CVSS 3.1 Critical EPSS 61% · top 0.9% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required, and a high EPSS score (0.60782) indicate severe risk and likely active exploitation.

What it is

CVE-2023-5830 is a critical improper authentication flaw (CWE-287) in ColumbiaSoft Document Locator's WebTools component, specifically the /api/authentication/login endpoint. Manipulating the Server argument allows an attacker to bypass authentication. The vendor addressed it in version 7.2 SP4 and 2021.1.

Impact

An unauthenticated remote attacker can bypass authentication on the login API, potentially gaining access to the application with the privileges of the impersonated or default account. Given the CVSS vector (C:H/I:H/A:H), full compromise of confidentiality, integrity, and availability is possible.

Attack surface

Reachable over the network via the /api/authentication/login endpoint of the WebTools component; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no public exploit references are provided; EPSS probability is 0.60782 (99.1st percentile), indicating a high likelihood of exploitation activity in the wild.

What to do

  • Upgrade Document Locator to version 7.2 SP4 or 2021.1 as recommended by the vendor.
  • If immediate upgrade is not possible, restrict network access to the /api/authentication/login endpoint to trusted networks or IP ranges.
  • Monitor and log authentication attempts to the WebTools API for anomalous Server argument values.
  • Apply network segmentation to limit exposure of the WebTools component to the internet.

Detection

  • Inspect web server and application logs for requests to /api/authentication/login with unusual or unexpected Server parameter values.
  • Alert on successful authentication events originating from untrusted or unexpected source IPs.
  • Correlate multiple failed login attempts followed by a successful login from the same source within a short window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://vuldb.com/?ctiid.243729 Permissions Required
https://vuldb.com/?id.243729 Third Party Advisory
https://vuldb.com/?ctiid.243729 Permissions Required
https://vuldb.com/?id.243729 Third Party Advisory

Track CVE-2023-5830 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.8CVE-2023-49105ownCloud Server WebDAV authentication bypass via pre-signed URLsownCloud core before 10.13.1 accepts pre-signed URLs even when the file owner has no signing-key configured, so the signature check is effectively sk…KEVEPSS 43%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed9.3CVE-2026-16232Check Point SmartConsole authentication bypass grants admin tokenCheck Point SmartConsole login contains an improper authentication flaw (CWE-287) that lets an unauthenticated remote attacker obtain an application …KEVEPSS 78%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed

Source: NIST National Vulnerability Database (record CVE-2023-5830), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.