Junglewise Threat Intelligence

CVE-2026-8360: Gladinet Triofox Server Agent NULL pointer dereference in WOSCommonUtil.dll

CVE-2026-8360 · Severity: high · CVSS 7.5 · Published 2026-05-27

Technologies: Gladinet Triofox Server Agent. Vendors: Gladinet.

Executive brief

Gladinet Triofox Server Agent is a software component used to connect local file servers to cloud storage. A vulnerability in how the software handles internal system information can allow a remote attacker to crash the service. This results in a denial-of-service condition, preventing users from accessing or managing their cloud-connected files through the agent.

Technical details

A NULL pointer dereference vulnerability exists in Gladinet Triofox Server Agent version 17.1.10488.57063. The issue resides in the WOSSysInfoGetDeviceInterface() function within WOSCommonUtil.dll, which is called by various modules including WOSProfileMgrModule.dll and WOSWebDavModule.dll. When no user is logged into the Triofox Server Agent Management Console, this function can return a NULL pointer that is subsequently dereferenced without a validity check. An unauthenticated remote attacker can trigger this condition by interacting with affected service endpoints (such as those on TCP port 7878), leading to a crash of the GladServerAgentService.exe process.

Affected products

  • Gladinet Triofox Server Agent 17.1.10488.57063

Timeline

  • 2026-05-27: advisory: Initial disclosure by Tenable and NVD

References

Related threats