Junglewise Threat Intelligence

CVE-2026-7382: MeWare PDKS sensitive information exposure

CVE-2026-7382 · Severity: medium · CVSS 6.5 · Published 2026-04-30

Executive brief

MeWare PDKS, a personnel attendance control system used to track employee entry and exit times, contains a security vulnerability that exposes sensitive personal information. An unauthorized individual could gain access to private data, potentially leading to privacy violations and the misuse of employee records. This could impact organizational compliance with data protection regulations and damage employee trust.

Technical details

A vulnerability classified as CWE-200 (Exposure of Sensitive Information) and CWE-359 (Exposure of Private Personal Information) exists in MeWare Software Development Inc. PDKS. The flaw allows an authenticated attacker with low privileges to access sensitive data over the network without user interaction. The root cause is an improper restriction of data access within the application's logic, which the advisory describes as allowing 'excavation' of information. The issue is addressed in version VMYR_3.5.2025117 and later.

Affected products

  • MeWare Software Development Inc. PDKS V16.20200313 to VMYR_3.5.2025117

Timeline

  • 2026-04-30: disclosed
  • 2026-04-30: advisory
  • 2026-06-06: other: Last modified date in NVD record.

References

Related threats