CVE-2026-2250
The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.36%
- CWE
- CWE-284, CWE-215
- Published
- 2026-02-11
- Last modified
- 2026-03-12
Affected products
- METIS Cyberspace Technology SA METIS WIC
- METIS Cyberspace Technology SA METIS WIC
Weakness type
Related vulnerabilities
- CVE-2026-79725 — Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation
- CVE-2026-81941 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-81046 — Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure...
- CVE-2026-88864 — Capgo SSO Provider Authentication Bypass via PostgREST Direct Write
- CVE-2026-78084 — Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4
- CVE-2026-50165 — alf.io has Improper Access Control for Organization Owners that Exposes System Secrets
- CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
- CVE-2026-19625 — IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities