CVE-2023-26580: Idattend Idweb

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers.

Affected products

  • Idattend Idweb: up to and including 3.1.052

Published 2023-10-25. Last modified 2026-06-17.