CVE-2026-40551
CVE-2026-40551 is a high-severity vulnerability with a CVSS 4.0 base score of 8.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-603.
Key facts
- Severity: High (CVSS 4.0 base score 8.4)
- EPSS exploit prediction: 0% (8th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-26045
- Weakness: CWE-603
- Published:
- Last modified:
Description
Multiple BinSoft products perform client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. The described issue affects all published versions. The vendor stated that this issue is a direct result of the architecture model in which the software is distributed, and that it will be mitigated with a corrected installation manual.
Frequently asked questions
- What is CVE-2026-40551?
- Multiple BinSoft products perform client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. The described issue affects all published versions. The vendor stated that this issue is a direct result of the architecture model in which the software is distributed, and that it will be mitigated with a corrected installation manual.
- How severe is CVE-2026-40551?
- CVE-2026-40551 has a CVSS 4.0 base score of 8.4, rated high severity.
- Is CVE-2026-40551 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (8th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-40551?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-40551 have an EU (EUVD) identifier?
- Yes. CVE-2026-40551 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-26045.
- When was CVE-2026-40551 published?
- CVE-2026-40551 was published on 2026-04-28 and last updated on 2026-09-30.
References
EU advisories (EUVD)
Other CWE-603 vulnerabilities
- CVE-2026-71187 — Critical (CVSS 9.8): The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An…
- CVE-2026-1363 — Critical (CVSS 9.8): IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing…
- CVE-2025-12868 — Critical (CVSS 9.8): New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated…
- CVE-2024-39375 — Critical (CVSS 9.8): TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator…
- CVE-2022-33139 — Critical (CVSS 9.8): A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All…
- CVE-2025-64119 — Critical (CVSS 9.3): A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery…