Threat intelligence dashboard
CVE-2026-100902high

Barco ClickShare CX-20 Gen2 Wallpaper Upload wallpaper improper validation of syntactic correctness of input

A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes improper validation of syntactic correctness of input. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Risk score

7.1

CVSS 4.0

Vendor
Barco
Product
ClickShare CX-20 Gen2
CWE
CWE-1286, CWE-20
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

ClickShare CX-20 Gen2

Barco

Version / rangeStatusType
02.26.00.0007affected—

Technical metrics

7.1

CVSS 4.0

Severity
high
Source
VulDB
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P

6.5

CVSS 3.1

Severity
medium
Source
VulDB
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:T/RC:R

6.5

CVSS 3.0

Severity
medium
Source
VulDB
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:T/RC:R

6.8

CVSS 2.0

Severity
medium
Source
VulDB
Vector
AV:N/AC:L/Au:S/C:N/I:N/A:C/E:POC/RL:TF/RC:UR