CVE-2016-1196: Cybozu Garoon

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.

Affected products

  • Cybozu Garoon: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.1.0 only; version 3.1.1 only; …

Published 2016-06-19. Last modified 2026-06-17.