CVE-2026-8480: Connection possible to the Administration portal with a revoked certificate
A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included)
A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain administrative access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 4.3.42 - Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 4.8.16 - Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 5.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8480?
CVE-2026-8480 has a medium severity score of 4.3.
How do I fix CVE-2026-8480?
To fix CVE-2026-8480, ensure all revoked client certificates are properly managed and restricted from accessing the captive-admin portal.
What systems are affected by CVE-2026-8480?
CVE-2026-8480 affects Stormshield Network Security versions 4.3.0 to 4.3.41, 4.4.0 to 4.8.15, and 5.0.2 EA to 5.0.5.
What is the risk associated with CVE-2026-8480?
The risk associated with CVE-2026-8480 is categorized as medium, with potential for unauthorized access due to revoked client certificates.
Is CVE-2026-8480 actively being exploited?
As of the latest information, there is no indication that CVE-2026-8480 is being actively exploited.