CVE-2026-4312: Dragonsoft Gcb/fcb Government Financial Cybersecurity Configuration Audit Software
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.
Affected products
- Dragonsoft Gcb/fcb Government Financial Cybersecurity Configuration Audit Software: affected versions not specified
Published 2026-03-17. Last modified 2026-06-17.