IGEL UMS Vulnerability Allows Remote Information Disclosure
Summary
CERT-Bund issued a security advisory regarding a high-severity vulnerability (CVSS 8.6) in IGEL Universal Management Suite (UMS). The vulnerability allows remote, anonymous attackers to disclose sensitive information. Affected versions are those prior to version 12.11.100 running on Linux and UNIX systems. Organizations using IGEL UMS should apply available mitigations or update to a patched version.
What changed
CERT-Bund published security advisory WID-SEC-2026-0957 addressing a critical information disclosure vulnerability in IGEL Universal Management Suite (UMS). The flaw has a CVSS Base Score of 8.6 (high) and a Temporal Score of 7.5 (high), with confirmed remote attack capability. The vulnerability affects all versions below 12.11.100 on Linux and UNIX operating systems. An unauthenticated, remote attacker can exploit this weakness to disclose system information.
Organizations using IGEL UMS should immediately identify whether their systems are running affected versions (prior to 12.11.100). Priority should be given to applying the vendor-supplied patch or implementing available mitigations. Since this is a remote, anonymous exploit vector, unpatched systems should be considered at immediate risk, particularly for government agencies and enterprises managing sensitive endpoints.
What to do next
- Identify whether IGEL UMS versions below 12.11.100 are running in your environment
- Apply the vendor patch or vendor-recommended mitigation immediately
- Verify patch implementation and monitor for exploitation attempts
Source document (simplified)
[WID-SEC-2026-0957] IGEL UMS: Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 8.6 (hoch) CVSS Temporal Score 7.5 (hoch) Remoteangriff ja Datum 01.04.2026 Stand 02.04.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
- UNIX
Produktbeschreibung
Die IGEL Universal Management Suite (UMS) ist eine Konsole zur Verwaltung von IGEL OS Endpunkten.
Produkte
01.04.2026
- IGEL UMS <12.11.100
Angriff
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IGEL UMS ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Named provisions
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.