PT-2026-21790 · Tattile · Basic+2

Gjoko Krstic

·

Publicado

2026-02-24

·

Atualizado

2026-02-27

·

CVE-2026-26342

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tattile Smart+, Vega, and Basic device families versions 1.181.5 and prior
Description The affected devices implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token, for example through interception, log exposure, or token reuse on a shared system, can continue to authenticate to the management interface until the token is revoked. This enables unauthorized access to device functions and data.
Recommendations Versions prior to 1.181.5 should be updated.

Exploit

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26342

Produtos afetados

Basic
Tattile Smart+
Vega