CVE-2026-31839

8.2

Striae · Striae

A high-severity integrity bypass vulnerability in Striae allows tampered confirmation packages to pass integrity checks due to improper hash-only validation.

Executive summary

Striae versions prior to 3.0.0 are vulnerable to an integrity bypass attack that allows for the processing of tampered digital confirmation packages.

Vulnerability

The application utilizes improper validation of integrity check values (CWE-354), where hash-only validation relies on manifest fields that an attacker can modify alongside package content. This bypass can be triggered by a local user who provides a malicious confirmation package.

Business impact

The ability to bypass integrity checks poses a significant risk to the reliability of forensic examination data. Because the system trusts manipulated hash fields, unauthorized modifications to confirmation packages could lead to the acceptance of fraudulent or compromised evidence, undermining the integrity of the entire examination workflow. The CVSS score of 8.2 reflects the high risk to data integrity despite the local attack vector.

Remediation

Immediate Action: Update the Striae package to version 3.0.0 or later to implement secure integrity validation.

Proactive Monitoring: Review audit logs for unexpected modifications to confirmation packages or anomalies in file processing workflows.

Compensating Controls: Ensure that systems processing these files are restricted to authorized personnel and utilize secure, isolated environments to prevent the introduction of untrusted packages.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the critical nature of the data handled by Striae, the integrity bypass represents a severe threat to operational outcomes. Administrators should prioritize the update to version 3.0.0 immediately to ensure that all confirmation packages are validated against secure integrity standards, thereby preventing the processing of tampered forensic data.

Sources