Junglewise Threat Intelligence

CVE-2026-46458: ICU Scandinavia Boomerang information disclosure in static XML files

CVE-2026-46458 · Severity: info · CVSS 7.1 · Published 2026-07-15

Executive brief

ICU Scandinavia Boomerang, a monitoring system used in laboratories and food safety environments to track temperatures and environmental data, is affected by a security flaw that exposes sensitive information. An unauthorized person can access internal configuration files containing plaintext passwords for service accounts and email servers. This could allow an attacker to gain further access to the organization's network or intercept automated alerts and reports.

Technical details

ICU Scandinavia Boomerang contains an information disclosure vulnerability (CWE-522) due to sensitive credential files being served as static HTTP resources. An unauthenticated remote attacker can retrieve plaintext service account and SMTP credentials by requesting specific XML files directly from the webroot. This vulnerability stems from insufficient protection of configuration files within the web server's public directory. The issue is resolved in version 2.4.18.029. A related vulnerability (CVE-2026-46459) also affects this product, involving missing authorization on data collection endpoints.

Affected products

  • ICU Scandinavia Boomerang All versions prior to 2.4.18.029

Timeline

  • 2026-07-15: advisory: Advisory published by CERT.PL and NVD
  • 2026-07-15: patched: Fix released in version 2.4.18.029

References

Related threats