CVE Vulnerabilities

CVE-2026-26721

Use of GET Request Method With Sensitive Query Strings

Published: Feb 20, 2026 | Modified: Feb 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensitive information via the sid query parameter.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

NameVendorStart VersionEnd Version
Global_facilities_management_softwareKeystorage20230721a (including)20230721a (including)

Potential Mitigations

References