CVE-2026-33243 | barebox up to 2025.09.2/2026.03.0 data authenticity (Duplicate CVE-2026-46728 / GHSA-3fvj-q26p-j6h4)
A vulnerability was found in barebox up to 2025.09.2/2026.03.0. It has been declared as critical. Impacted is an unknown function. The manipulation results in insufficient verification of data authenticity.
This vulnerability is reported as CVE-2026-33243. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
A duplicate CVE-2026-46728 appears to be assigned to this entry.