Vulnerability Description
Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not checked before being dereferenced.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/TRA-2026-45
- https://www.tenable.com/security/research/TRA-2026-45
FAQ
What is CVE-2026-8360?
CVE-2026-8360 is a vulnerability with a CVSS score of 7.5 (HIGH). Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the...
How severe is CVE-2026-8360?
CVE-2026-8360 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-8360?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.