rootpwn

critical · CVSS v3 9.8 · CVSS v4 4.1 · EPSS 0.00177

CVE-2026-92378

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Und…

Description

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.

Scores

Severity
critical
CVSS v2
7.5
CVSS v3
9.8
CVSS v4
4.1
EPSS
0.00177

← All CVEs