ThreatCluster

Multiple Vulnerabilities Discovered in kerwincui FastBee Software

First seen 3 May 2026, 23:46 UTC Nvd.Nist 97% similarity 72

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in kerwincui FastBee versions up to 1.2.1. CVE-2026-7676 affects the Tool Download Endpoint, allowing path traversal through the fileName argument in the ToolController.download function. CVE-2026-7677 impacts the System Notice Handler, enabling cross-site scripting via the noticeContent argument in the SysNoticeController.Add function. Both vulnerabilities can be exploited remotely, and the exploits have been publicly disclosed. The vendor was contacted prior to disclosure but did not respond. These vulnerabilities pose significant risks to users of the FastBee software, potentially leading to unauthorized access and data manipulation. Immediate attention is required for affected systems to mitigate these risks.

Key Points: • CVE-2026-7676 allows path traversal in FastBee's Tool Download Endpoint. • CVE-2026-7677 enables cross-site scripting in the System Notice Handler. • Both vulnerabilities can be exploited remotely and have been publicly disclosed.

ThreatCluster AI

Timeline

2026-05-03
CVE-2026-7676 published
2026-05-03
CVE-2026-7677 published

Community

Browse all →