PT-2026-40455 · Espressif Systems · Arduino-Esp32

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2026-42855

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions arduino-esp32 versions prior to 3.3.8
Description The WebServer Digest authentication implementation computes the authentication hash using the URI field from the client's Authorization header without verifying that it matches the actual requested URI. This allows an attacker with a valid digest response for one URI to authenticate requests to a different protected URI, bypassing per-resource access control.
Recommendations Update to version 3.3.8.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-42855

Affected Products

Arduino-Esp32