Published:2026/08/28  Last Updated:2026/08/28

JVN#04485476
Multiple vulnerabilities in SOY series

Overview

SOY series provided by Tsuyoshi Saito contain multiple vulnerabilities.

Products Affected

CVE-2026-73827, CVE-2026-77838

  • SOY Calendar ver 2.4.0 and earlier
CVE-2026-78032
  • SOY CMS ver 3.24.0 and earlier
CVE-2026-78238
  • SOY Gallery ver 2.0.0 and earlier
The SOY series provided by Brassica, Inc. is not affected by these vulnerabilities.

Description

SOY series provided by Tsuyoshi Saito contain multiple vulnerabilities listed below.

  • Cross-site Scripting (CWE-79)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 4.8
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Base Score 5.4
    • CVE-2026-73827, CVE-2026-77838, CVE-2026-78238
  • Deserialization of Untrusted Data (CWE-502)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
    • CVE-2026-78032

Impact

  • An arbitrary script may be executed on the web browser of the user who is logging in to the product (CVE-2026-73827, CVE-2026-77838, CVE-2026-78238).
  • Arbitrary code may be executed by an attacker with the web server privileges (CVE-2026-78032).

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Shogo Kumamaru of LAC Co., Ltd. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-73827
CVE-2026-77838
CVE-2026-78032
CVE-2026-78238
JVN iPedia JVNDB-2026-000125