CVE-2023-26760: Smeup ERP

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.

Affected products

  • Smeup ERP: version tokyo_v6r1m220406 only

Published 2023-02-27. Last modified 2026-06-17.