CVE-2023-36002: Proofpoint Insider Threat Management Server

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.

Affected products

  • Proofpoint Insider Threat Management Server: before 7.14.3 (fixed in 7.14.3)

Published 2023-06-27. Last modified 2026-06-17.