{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-1433",
        "assignerOrgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
        "state": "PUBLISHED",
        "assignerShortName": "Canon_EMEA",
        "dateReserved": "2026-01-26T12:49:23.159Z",
        "datePublished": "2026-07-06T08:12:49.571Z",
        "dateUpdated": "2026-07-06T18:54:02.174Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
                "shortName": "Canon_EMEA",
                "dateUpdated": "2026-07-06T08:12:49.571Z"
            },
            "title": "uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-522",
                            "description": "CWE-522: Insufficiently Protected Credentials",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "Not applicable"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "NT-ware",
                    "product": "uniFLOW ULM (Universal Login Manager) Standalone",
                    "platforms": [
                        "Web Application"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "5.10",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "uniFLOW Universal Login Manager (ULM) Standalone\ncontains an information disclosure vulnerability that may allow an\nauthenticated administrator to access sensitive configuration information\nthrough the ULM Remote User Interface (RUI). Exploitation requires\nadministrative privileges and may disclose configuration data associated with\nSMTP or LDAP integrations. ULM deployments connected to uniFLOW Server or\nuniFLOW Online are not affected.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "uniFLOW Universal Login Manager (ULM) Standalone\ncontains an information disclosure vulnerability that may allow an\nauthenticated administrator to access sensitive configuration information\nthrough the ULM Remote User Interface (RUI). Exploitation requires\nadministrative privileges and may disclose configuration data associated with\nSMTP or LDAP integrations. ULM deployments connected to uniFLOW Server or\nuniFLOW Online are not affected."
                        }
                    ]
                }
            ],
            "tags": [
                "x_cemea",
                "x_nt_ware",
                "x_subsidiary"
            ],
            "references": [
                {
                    "url": "https://www.canon-europe.com/psirt/advisory-information",
                    "tags": [
                        "vendor-advisory"
                    ]
                },
                {
                    "url": "https://ntware.atlassian.net/wiki/spaces/SA/pages/13659504652/2026+Security+Advisory+ULM+Potential+Information+Disclosure",
                    "tags": [
                        "vendor-advisory",
                        "mitigation"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "ADJACENT",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "HIGH",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "NONE",
                        "subConfidentialityImpact": "LOW",
                        "vulnIntegrityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "NONE",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 4.8,
                        "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Sam Shepherd working with BAE Systems",
                    "type": "reporter"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.2"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-06T18:53:50.994716Z",
                                "id": "CVE-2026-1433",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-06T18:54:02.174Z"
                }
            }
        ]
    }
}