CVE-2026-46459: Icu Scandinavia Boomerang

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database. This issue has been fixed in version 2.4.18.029

Affected products

Published 2026-07-15. Last modified 2026-07-15.