CVE-2026-5426
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
- Affected products
- Knowledgedeliver
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 1.0% (60th percentile)
- Weakness
- CWE-321, CWE-502
- NVD status
- Awaiting Analysis
- Published
- 2026-04-16
- Attack patterns
- CAPEC-586
CVE-2026-5426 at NVD
1 known exploit for CVE-2026-5426
Proof-of-concept code and exploit modules indexed by Sploitus