CVE-2026-33243 | barebox up to 2025.09.2/2026.03.0 data authenticity (GHSA-3fvj-q26p-j6h4)
A vulnerability was found in barebox up to 2025.09.2/2026.03.0. It has been declared as critical. Impacted is an unknown function. The manipulation results in insufficient verification of data authenticity.
This vulnerability is reported as CVE-2026-33243. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.