Mindbreeze InSpire Vulnerabilities

This page lists known security vulnerabilities found in Mindbreeze InSpire. The article titles contain the Mindbreeze issue number and, in the case of third-party software, the official CVE number. Information about the affected components, severity level, current status and how to prevent the issue as well as hotfix information if applicable, can be found on the detail pages. You can also use the full text search to find specific vulnerabilities.

If you have found a possible security vulnerability, please contact Mindbreeze InSpire Support at support@mindbreeze.com providing detailed information about the problem found.

icon vulnerabilities

Vulnerabilities

ID: MINDBREEZE42880 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: 8.8 High Status: Final First published: August 5, 2026 CVEs: CVE-2026-6473, CVE-2026-6472, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638 
ID: MINDBREEZE42872 Affected Components: Mindbreeze InSpire Severity: 7.5 High Status: Final First published: August 5, 2026 CVEs: CVE-2025-6021, CVE-2026-6732 
ID: MINDBREEZE42861 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: Medium Status: Final First published: August 5, 2026 CVEs: CVE-2026-42498,CVE-2026-41293,CVE-2026-41284,CVE-2026-43515,CVE-2026-43514,CVE-2026-43513,CVE-2026-43512 
ID: MINDBREEZE42851 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: 5.3 Medium Status: Final First published: August 5, 2026 CVEs: CVE-2026-3219, CVE-2026-6357 Summary pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file pip self-update functionality can import newly installed modules after wheel installation  Hotfix Information 
ID: MINDBREEZE42850 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: Medium Status: Final First published: August 5, 2026 CVEs: CVE-2026-22007,CVE-2026-22013,CVE-2026-22016,CVE-2026-22018,CVE-2026-22021,CVE-2026-23865,CVE-2026-34282,CVE-2026-34268 
ID: MINDBREEZE42734 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: 7.8 High Status: Final First published: August 5, 2026 CVEs: CVE-2026-43284 Summary kernel: local privilege escalation (DirtyFrag)  Hotfix Information Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: Mindbreeze InSpire 26.3 ReleaseMindbreeze InSpire SaaS 26.3 Release 
ID: MINDBREEZE42717 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: 9.6 Critical Status: Final First published: August 5, 2026 CVEs: See Summary 
ID: MINDBREEZE42698 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: 7.9 High Status: Final First published: August 5, 2026 CVEs: CVE-2026-31431 Summary kernel: local privilege escalation (CopyFail)  Hotfix Information Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: Mindbreeze InSpire 26.3 ReleaseMindbreeze InSpire SaaS 26.3 Release 
ID: MINDBREEZE42693 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: 7.5 High Status: Final First published: August 5, 2026 CVEs: CVE-2026-41080, CVE-2026-45186 Summary libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.  Hotfix Information 
ID: MINDBREEZE42440 Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS Severity: Critical Status: Affected First published: August 5, 2026 CVEs: CVE-2026-34483 (GHSA-rv64-5gf8-9qq8), CVE-2026-29145 (GHSA-95jq-rwvf-vjx4),  CVE-2026-29129 (GHSA-69cc-cv78-qc8g),  CVE-2026-34500 (GHSA-24j9-x2wg-9qv6, CVE-2026-29146 (GHSA-h468-7pvh-8vr8),CVE-2026-25854 (GHSA-9m3c-qcxr-9x87), CVE-2026-34487 (GHSA-x4m4-345f-5h5g), CVE-2026-24880 (GHSA-563x-q5rq-57qp),CVE-2026-32990 (GHSA-8mc5-53m5-3qj2)