CVE-2026-34025

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability in the login process. The application restricts user logins based on the IP address associated with a branch location, but the client IP address is derived from the HTTP X-Forwarded-For header when that header is present. An attacker with valid branch user credentials can manipulate the X-Forwarded-For header during login to spoof the expected branch IP address and obtain a valid authenticated session from an unauthorized network location.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jun 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-15 12:16

Updated : 2026-06-17 10:38


NVD link : CVE-2026-34025

Mitre link : CVE-2026-34025

CVE.ORG link : CVE-2026-34025


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing