Executive brief
CAYIN CMS-WS and CMS-SE are media management and content delivery systems used by broadcasters and media companies. An unauthenticated attacker can bypass access controls and retrieve a list of media files, exposing sensitive information about the organization's video and audio assets without requiring any credentials or login.
Technical details
This vulnerability is a missing authentication flaw in CAYIN CMS-WS and CMS-SE that allows unauthenticated remote attackers to access specific functionality that retrieves media file lists. The vulnerability is network-accessible and requires no authentication credentials, user interaction, or complex preconditions to exploit. An attacker can query the affected systems directly to enumerate media assets, resulting in information disclosure (confidentiality impact). Patches are available: CMS-WS should be updated to version 1.0.26198 or later, and CMS-SE should be updated to version 11.0.26198 or later.
Affected products
- CAYIN Technology CMS-WS 1.0.25336 and earlier
- CAYIN Technology CMS-SE 11.0.25336 and earlier
Timeline
- 2026-08-26: disclosed