CVE-2026-4312
gcb\/fcb_government_financial_cybersecurity_configuration_audit_software: Missing Authentication for Critical Function (CVE-2026-4312)
criticalEPSS 0.8%
Description
GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
dragonsoftgcb\/fcb_government_financial_cybersecurity_configuration_audit_software
Metrics
Show all metrics
Severity
critical
89.34
no public PoC known
9.8
9.3
Published
2026-03-17 07:29 UTC
CWE-306
Weakness classes (CWE)
CWE-306Base
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
cwe.mitre.org →