References https://www.twcert.org.tw/tw/cp-132-10784-4f67d-1.html https://cnc.nptu.edu.tw/p/406-1007-193516,r1042.php?Lang=zh-tw https://lic.nuk.edu.tw/p/406-1012-96349,r73.php?Lang=zh-tw https://www.nchu.edu.tw/news-detail.php?id=61523 https://www.tcrc.edu.tw/new/new-list/gcb-fcb-missing-authentication https://www.dragonsoft.com/pagenation/D-GCB.html https://net.nthu.edu.tw/netsys/sewcurity:cybersecurity_intelligence_advisory https://cc.ncku.edu.tw/var/file/213/1213/img/4803/661877098.pdf https://net.nthu.edu.tw/netsys/en:mailing:announcement:20260320_22 https://cve.imfht.com/detail/CVE-2026-4312?lang=en https://www.dragonsoft.com/ https://www.sunnet-cyber.com/dragonsoft-gcb
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication BypassPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCCVE-2026-48558: SimpleHelp <=5.5.15 - OIDC JWT Authentication BypassPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassPoCCVE-2026-86207: N-able N-central - Authentication BypassPoCCVE-2026-18577: N-able N-central < 2026.3.1.10 - Authentication Bypass鎧應科技|CAYIN CMS-WS/CMS-SE - Missing AuthenticationPoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment Deletion