CRITICAL
Unauthenticated Remote File Download in Explorance Blue
Published Jan 28, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.61%
Description
Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configurations, this flaw can be leveraged to achieve remote code execution.
Affected products
-
- Version 0StatusaffectedConstraints<8.14.13
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Explorance | Blue | unaffected |
|
- < 8.14.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0004.md third-party-advisoryThird Party Advisory
- https://online-help.explorance.com/blue/articles/security-advisories-(january-2026) vendor-advisoryVendor Advisory
- https://online-help.explorance.com/blue/articles/security-advisory:-cve-2025-57795 vendor-advisoryVendor Advisory
- https://www.explorance.com/products/blue product
| Link | Providers | Tags |
|---|---|---|
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0004.md | third-party-advisoryThird Party Advisory | |
| https://online-help.explorance.com/blue/articles/security-advisories-(january-2026) | vendor-advisoryVendor Advisory | |
| https://online-help.explorance.com/blue/articles/security-advisory:-cve-2025-57795 | vendor-advisoryVendor Advisory | |
| https://www.explorance.com/products/blue | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mandiant
Published Jan 28, 2026
Updated Jan 28, 2026
Reserved Aug 19, 2025
Link CVE-2025-57795
CISA Vulnrichment
Updated Jan 28, 2026