Executive brief
ICU Scandinavia Boomerang, a monitoring system used in laboratories and food safety environments to track temperatures and environmental data, is affected by a security flaw that exposes sensitive information. An unauthorized person can access internal configuration files containing plaintext passwords for service accounts and email servers. This could allow an attacker to gain further access to the organization's network or intercept automated alerts and reports.
Technical details
ICU Scandinavia Boomerang contains an information disclosure vulnerability (CWE-522) due to sensitive credential files being served as static HTTP resources. An unauthenticated remote attacker can retrieve plaintext service account and SMTP credentials by requesting specific XML files directly from the webroot. This vulnerability stems from insufficient protection of configuration files within the web server's public directory. The issue is resolved in version 2.4.18.029. A related vulnerability (CVE-2026-46459) also affects this product, involving missing authorization on data collection endpoints.
Affected products
- ICU Scandinavia Boomerang All versions prior to 2.4.18.029
Timeline
- 2026-07-15: advisory: Advisory published by CERT.PL and NVD
- 2026-07-15: patched: Fix released in version 2.4.18.029