CVE-2024-40407: Cybelesoft Thinfinity Workspace

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.

Affected products

  • Cybelesoft Thinfinity Workspace: before 7.0.2.113 (fixed in 7.0.2.113)

Published 2024-11-13. Last modified 2026-06-17.