CERT Polska disclosed two vulnerabilities in ICU Scandinavia Boomerang that could let unauthenticated remote attackers access sensitive data and interact with system functions without authorization. The issues, tracked as CVE-2026-46458 and CVE-2026-46459, affect all versions before 2.4.18.029 and were publicly listed alongside a brief industry notice highlighting the affected product and CVE identifiers.
CVE-2026-46458 allows plaintext service account and SMTP credentials to be retrieved from XML files exposed over static HTTP because the credentials were insufficiently protected. CVE-2026-46459 is a missing authorization flaw in device receiver endpoints that can let unauthenticated attackers read full facility configurations and write unauthorized data to the sensor database. ICU Scandinavia fixed both flaws in Boomerang 2.4.18.029 after responsible reporting by Marek Figielski of vanilla.pl, with disclosure coordinated by CERT Polska.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-15, CERT Polska disclosed two vulnerabilities in ICU Scandinavia Boomerang: an information disclosure issue exposing plaintext credentials and a missing authorization flaw enabling unauthorized configuration access and sensor database writes.
The two vulnerabilities, CVE-2026-46458 and CVE-2026-46459, were fixed in Boomerang version 2.4.18.029. All versions before 2.4.18.029 are affected.
Marek Figielski of vanilla.pl responsibly reported two vulnerabilities affecting ICU Scandinavia Boomerang, and CERT Polska coordinated the disclosure process.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.