CVE-2026-46459: Icu Scandinavia Boomerang
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database. This issue has been fixed in version 2.4.18.029
Affected products
- Icu Scandinavia Boomerang: before 2.4.18.029 (fixed in 2.4.18.029)
Published 2026-07-15. Last modified 2026-07-15.