CVE-2026-26418

Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tcs:cognix_platform:3.0:*:*:*:*:*:*:*

History

10 Mar 2026, 18:33

Type Values Removed Values Added
CPE cpe:2.3:a:tcs:cognix_platform:3.0:*:*:*:*:*:*:*
First Time Tcs cognix Platform
Tcs
References () https://github.com/aksalsalimi/CVE-2026-26418 - () https://github.com/aksalsalimi/CVE-2026-26418 - Third Party Advisory
References () https://github.com/aksalsalimi/cognix-recon-client-security-advisories - () https://github.com/aksalsalimi/cognix-recon-client-security-advisories - Third Party Advisory
References () https://www.tcs.com/what-we-do/services/cognitive-business-operations/solution/cognix-platform-business-agility-enhanced-cx - () https://www.tcs.com/what-we-do/services/cognitive-business-operations/solution/cognix-platform-business-agility-enhanced-cx - Product
Summary
  • (es) Falta de autenticación y autorización en la API web de Tata Consultancy Services Cognix Recon Client v3.0 permite a atacantes remotos acceder a la funcionalidad de la aplicación sin restricciones a través de la red.

06 Mar 2026, 10:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-284

05 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 19:16

Updated : 2026-03-10 18:33


NVD link : CVE-2026-26418

Mitre link : CVE-2026-26418

CVE.ORG link : CVE-2026-26418


JSON object : View

Products Affected

tcs

  • cognix_platform
CWE
CWE-284

Improper Access Control