PT-2026-21790 · Tattile · Basic+2
Gjoko Krstic
·
Published
2026-02-24
·
Updated
2026-02-27
·
CVE-2026-26342
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tattile Smart+, Vega, and Basic device families versions 1.181.5 and prior
Description
The affected devices implement an authentication token (
X-User-Token) with insufficient expiration. An attacker who obtains a valid token, for example through interception, log exposure, or token reuse on a shared system, can continue to authenticate to the management interface until the token is revoked. This enables unauthorized access to device functions and data.Recommendations
Versions prior to 1.181.5 should be updated.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Basic
Tattile Smart+
Vega