LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-26418

CVE-2026-26418 - Vulnerability Analysis

HighCVSS: 7.5

Last Updated: March 6, 2026

Tata Consultancy Services Cognix Recon Client - Broken Access Control

Published: March 5, 2026Updated: March 6, 2026PoC AvailableRemote Exploitable

Overview

Tata Consultancy Services Cognix Recon Client v3.0 contains a broken access control caused by missing authentication and authorization in the web API, letting remote attackers access application functionality without restriction, exploit requires network access.

Severity & Score

Severity: High
CVSS Score: 7.5
EPSS Score: 5.9%(Probability of exploitation in next 30 days)

Impact

Remote attackers can access application functionality without restriction, potentially leading to unauthorized data access or manipulation.

Mitigation

Update to the latest version with proper authentication and authorization implemented.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 8, 2026

🟠 CVE-2026-26418 - High (7.5) Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-26418/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-26418
Severity
High
CVSS Score
7.5
Type
broken_access_control
Status
unconfirmed
EPSS
5.9%
Social Posts
1

CWE

  • CWE-284

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Score

5.9%Probability of exploitation in the next 30 days