Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

GFI Archiver Authentication Bypass on Remote Access

CVE-2026-2039
Summary

A vulnerability in GFI Archiver allows attackers to bypass authentication and potentially access sensitive areas without a password. This could lead to unauthorized access to sensitive data. To protect your system, update GFI Archiver to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
gfi archiver 15.10 –
Original title
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Aut...
Original description
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the configuration of the MArc.Store.Remoting.exe process, which listens on port 8018. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM. Was ZDI-CAN-28597.
nvd CVSS3.1 9.8
Vulnerability type
CWE-862 Missing Authorization
Published: 20 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026