CVE-2026-22614 MEDIUM

CVE-2026-22614

Vendor Eaton
Product EasySoft
Weakness CWE-257
Published March 10, 2026
Last update March 10, 2026

CVSS base score

6.1/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine could potentially read the sensitive information stored and tamper with the project file. This security issue has been fixed in the latest version of Eaton EasySoft which is available on the Eaton download centre.

Key dates

02Disclosure timeline

March 10, 2026 CVE published
March 10, 2026 Record updated