S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 19, 2025

CVE-2023-26258 Scanner

CVE-2023-26258 Scanner - Authentication Bypass vulnerability in Arcserve UDP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-26258
9.8
CVSS

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Arcserve UDP is a comprehensive data protection solution utilized by businesses worldwide to safeguard their critical data. It is designed to back up, replicate, and recover data across different environments, including physical and virtual infrastructures. Organizations use this solution to ensure business continuity and minimize data loss during disasters. Admins and IT professionals rely on its robust features to manage data protection across global networks. Arcserve UDP is known for its scalability and flexibility, allowing it to adapt to the varying needs of small enterprises and large corporations alike. The software supports seamless integration with various platforms, thereby ensuring that diverse data and applications are consistently protected.

The vulnerability detected in Arcserve UDP involves an authentication bypass, which could potentially allow unauthorized access. This particular issue arises from the endpoint /WebServiceImpl/services/FlashServiceImpl leaking an authentication token. The leaked token can then be employed at /WebServiceImpl/services/VirtualStandbyServiceImpl to acquire a session with administrative privileges. Such unauthorized access could enable attackers to execute any task as an administrator. This flaw is critical as it undermines the security model of the application by bypassing authentication controls. It poses a significant risk of unauthorized data manipulation and system compromise.

The authentication bypass vulnerability exploits a flaw in the way Arcserve UDP handles session tokens. Specifically, the getVersionInfo method at the endpoint /WebServiceImpl/services/FlashServiceImpl exposes the AuthUUID token. This token is intended for internal validation but can be exploited by malicious actors when improperly handled. After obtaining this token, attackers can use it in subsequent requests to the endpoint /WebServiceImpl/services/VirtualStandbyServiceImpl. This process grants them a valid session, potentially allowing for full administrative actions. The ability to bypass standard security measures with this token highlights a severe lapse in access control mechanisms within the affected versions.

Exploiting the authentication bypass vulnerability could have severe consequences for affected systems. Attackers gaining unauthorized access can perform actions as though they were legitimate administrators, leading to unauthorized data access, manipulation, or deletion. The system's integrity and availability can be severely compromised, leading to potential data loss or corruption. Furthermore, malicious entities might deploy additional exploits or malware within the compromised environment. The disruption of critical backup functionalities and unauthorized configuration changes could pose significant risks to organizations relying on Arcserve UDP for data protection.

REFERENCES

Solution Advice
  • Implement stricter access controls and proper handling of authentication tokens.
  • Update Arcserve UDP to a version that addresses this vulnerability.
  • Regularly review and monitor access logs for any unusual activity or unauthorized access attempts.
  • Deploy additional layers of security such as multi-factor authentication to enhance access control.
  • Conduct periodic security audits and vulnerability assessments to ensure system integrity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-26258 Scanner - Authentication Bypass vulnerability in Arcserve UDP | S4E