Junglewise Threat Intelligence

CVE-2026-34023: Wertheim SafeController incorrect authorization in WebSocket communication

CVE-2026-34023 · Severity: info · CVSS 7.1 · Published 2026-06-15

Technologies: Wertheim SafeController Software. Vendors: Wertheim.

Executive brief

Wertheim SafeController is a professional software suite used by banks and financial institutions to manage safe deposit boxes and vault rooms. A security flaw in the system's communication protocol allows a staff member with low-level access at one branch to manipulate messages and gain control over safe deposit boxes or resources at other branches. This could lead to unauthorized access to physical security infrastructure and sensitive customer assets across different locations.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the WebSocket communication used by the Wertheim SafeController WebMessageBroker. The flaw resides in how the application validates controller identifiers within WebSocket messages. An authenticated attacker with low-privileged branch credentials can intercept and modify these messages, replacing their authorized branch/controller IDs with those of other branches. This bypasses intended logical isolation, allowing the attacker to invoke restricted functions, such as remotely activating or opening safe deposit boxes outside of their assigned jurisdiction. When combined with other vulnerabilities in the suite (such as path traversal or broken access control), this can contribute to a full system compromise.

Affected products

  • Wertheim SafeController Software AssemblyVersion 6.15.8328.28014

Timeline

  • 2023-04-03: other: Vulnerability discovered by SEC Consult
  • 2026-06-15: advisory: Public disclosure by SEC Consult and NVD publication

References

Related threats