CVE-2026-26417

A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tcs:cognix_platform:3.0:*:*:*:*:*:*:*

History

10 Mar 2026, 18:49

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de control de acceso roto en la funcionalidad de restablecimiento de contraseña de Tata Consultancy Services Cognix Recon Cliente v3.0 permite a usuarios autenticados restablecer contraseñas de cuentas de usuario arbitrarias a través de solicitudes manipuladas.
First Time Tcs cognix Platform
Tcs
CPE cpe:2.3:a:tcs:cognix_platform:3.0:*:*:*:*:*:*:*
References () https://github.com/aksalsalimi/CVE-2026-26417 - () https://github.com/aksalsalimi/CVE-2026-26417 - Third Party Advisory
References () https://github.com/aksalsalimi/cognix-recon-client-security-advisories - () https://github.com/aksalsalimi/cognix-recon-client-security-advisories - Third Party Advisory

06 Mar 2026, 10:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-284

05 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 19:16

Updated : 2026-03-10 18:49


NVD link : CVE-2026-26417

Mitre link : CVE-2026-26417

CVE.ORG link : CVE-2026-26417


JSON object : View

Products Affected

tcs

  • cognix_platform
CWE
CWE-284

Improper Access Control