Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-28698: Pronetiqs IntraVUE exposes sensitive system data

CVE-2026-28698 · published 2 months ago
Summary

Pronetiqs IntraVUE versions 3.2.1a14 and earlier allow unauthorized access to system files and data. This could lead to sensitive information being exposed, potentially compromising system security and integrity. Update to the latest version to mitigate this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
pronetiqs panduit intravue <= 3.2.1a14
Original advisory text
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.
Severity
9.2 Critical
CVSS 3.1: 8.6 (NVD)
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere
Timeline
Published23 Jul 2026
Updated27 Sep 2026
First seen23 Jul 2026
Sources
CVE-2026-28698 · MITRE
Track software like this
Free during beta