Vulnerability Description
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communication used by the SafeController WebMessageBroker. An authenticated attacker with valid low-privileged branch user credentials can manipulate WebSocket messages by specifying controller identifiers belonging to other branches. This allows the attacker to access restricted functions and resources in other branches, including activating boxes outside of the user's authorized branch.
Related Weaknesses (CWE)
References
- https://r.sec-consult.com/wertheim
- https://wertheim-safes.com/safe-deposit-box-management/
- https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabili
FAQ
What is CVE-2026-34023?
CVE-2026-34023 is a documented vulnerability. The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communication used by the SafeController WebMessageBroker. An ...
How severe is CVE-2026-34023?
CVSS scoring is not yet available for CVE-2026-34023. Check NVD for updates.
Is there a patch for CVE-2026-34023?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.