Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 4.0.0
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:coolercontrol:coolercontrold:*:*:*:*:*:*:*:* |
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coolercontrol
Coolercontrol coolercontrold |
|
| Vendors & Products |
Coolercontrol
Coolercontrol coolercontrold |
Wed, 08 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites | |
| Title | Permissive Cross-domain Policy with Untrusted Domains in coolercontrold | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-04-08T14:10:15.915Z
Reserved: 2026-04-01T05:33:27.052Z
Link: CVE-2026-5302
Updated: 2026-04-08T14:10:05.238Z
Status : Analyzed
Published: 2026-04-08T13:16:43.403
Modified: 2026-04-16T00:40:11.723
Link: CVE-2026-5302
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:21:50Z