CVE-2014-1996: Cybozu Garoon

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbitrary code or cause a denial of service, via an API call.

Affected products

  • Cybozu Garoon: version 3.7 only; version 3.7.0 only

Published 2014-07-20. Last modified 2026-06-17.