Junglewise Threat Intelligence

CVE-2026-8673: syslink software AG Avantra unprotected transport of credentials

CVE-2026-8673 · Severity: medium · CVSS 5.9 · Published 2026-05-22

Technologies: Avantra. Vendors: Avantra.

Executive brief

Avantra, an operations management platform for SAP systems, contains a vulnerability where login credentials are transmitted over unencrypted or insufficiently protected channels. This flaw could allow an attacker with network access to intercept sensitive administrative credentials during transmission. If exploited, this could lead to unauthorized access to the management platform and the underlying systems it monitors.

Technical details

A vulnerability classified as CWE-523 (Unprotected Transport of Credentials) exists in syslink software AG Avantra prior to version 25.3.0. The software fails to adequately encrypt or protect sensitive authentication data during transit across the network. An attacker positioned on the network path could perform a sniffing attack to capture these credentials. While the CNA (Switzerland Government Common Vulnerability Program) rates this as Medium complexity requiring high privileges, the lack of transport layer security for credentials poses a significant risk of account takeover. The issue is addressed in Avantra version 25.3.0.

Affected products

  • syslink software AG Avantra before 25.3.0

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory
  • 2026-06-02: other: NVD analysis updated

References