PT-2026-61045 · Allegro · Allegro

·

CVE-2026-16211

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

2.6

Low

VectorAV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions allegro versions prior to bcf65b994ef29fb3fc2e10b660e6288723d5209e
Description A race condition exists in the Hostname Allocation Handler component within the AssetLastHostname.increment hostname() function located in the src/ralph/assets/models/assets.py file. This issue occurs when the counter argument is manipulated, potentially allowing an attacker to exploit the timing of concurrent operations. A race condition is a situation where the behavior of software depends on the relative timing of events, such as the order in which threads are scheduled.
Recommendations Update allegro to version bcf65b994ef29fb3fc2e10b660e6288723d5209e or later. As a temporary mitigation, restrict access to the AssetLastHostname.increment hostname() function to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16211

Affected Products

Allegro