Executive brief
DrangSoft GCB/FCB Audit Software, used for government and financial cybersecurity configuration auditing, contains a critical security flaw. An unauthenticated attacker can remotely access internal application interfaces to create a new administrative account. This allows a complete takeover of the software, potentially compromising sensitive audit data and the security posture of the organization.
Technical details
A Missing Authentication vulnerability (CWE-306) exists in the GCB/FCB Audit Software developed by DrangSoft (also known as DragonSoft). The flaw is located within specific API endpoints that fail to verify the identity of the requester before performing sensitive operations. A remote, unauthenticated attacker can exploit this by sending crafted requests to these APIs to register a new account with administrative privileges. This leads to a full compromise of the application's integrity and confidentiality. The vulnerability is addressed in version 20260108 and later.
Affected products
- DrangSoft (DragonSoft) GCB/FCB Audit Software before 20260108
Timeline
- 2026-03-17: disclosed
- 2026-03-17: advisory
- 2026-01-08: patched: Fixed in version 20260108