PT-2026-21790 · Tattile · Basic+2

Gjoko Krstic

·

Published

2026-02-24

·

Updated

2026-02-27

·

CVE-2026-26342

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tattile Smart+, Vega, and Basic device families versions 1.181.5 and prior
Description The affected devices implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token, for example through interception, log exposure, or token reuse on a shared system, can continue to authenticate to the management interface until the token is revoked. This enables unauthorized access to device functions and data.
Recommendations Versions prior to 1.181.5 should be updated.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26342

Affected Products

Basic
Tattile Smart+
Vega