CVE-2022-27968
Description
Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of monitored files and profiles via a crafted GET request sent to /WebApp/SettingsFileMonitor/GetFileMonitorProfiles.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cynet 360 Web Portal before v4.5 exposes a list of monitored files and profiles via a crafted GET request.
Vulnerability
A crafted GET request sent to the /WebApp/SettingsFileMonitor/GetFileMonitorProfiles endpoint in Cynet 360 Web Portal before v4.5 allows an attacker to enumerate file monitoring profiles and associated file paths without proper authorization [1]. The vulnerability exists due to missing access controls on this API endpoint.
Exploitation
An attacker can exploit this by sending a direct GET request to the vulnerable endpoint. No authentication or special privileges are required; the attacker only needs network access to the Cynet 360 Web Portal. The response contains the list of file monitor profiles and monitored file paths [1].
Impact
Successful exploitation results in unauthorized information disclosure of file monitoring configurations. This can provide an attacker with insight into which files are being monitored by the security platform, potentially revealing sensitive file paths or system configurations that could be targeted in further attacks [1].
Mitigation
Upgrade to Cynet 360 Web Portal v4.5 or later, which addresses this issue [1]. No workaround is mentioned in the available references.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Cynet/360 Web Portaldescription
- Range: <4.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.cynet.com/platform/mitrex_refsource_MISC
- www.srlabs.de/bites/edr-securitymitrex_refsource_MISC
News mentions
0No linked articles in our index yet.