CVE-2026-72506CWE-941

CVE-2026-72506

Medium · published August 13, 2026

CVSS v3.0
5.4
EPSS
0%
Percentile
7.3
In the wild
Unconfirmed
What it is

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.

The record
Technical detail
CVSS v3.0
5.4 · MEDIUM
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00177 · 7.3th percentile
Weakness
CWE-941 · Incorrectly Specified Destination in a Communication Channel
Published
2026-08-13T09:17Z
References (3)
EPSS history
Timeline
  • 13 AUG 04:07Z
    VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication…
    cvelistv5