CVE-2026-64827
CVE-2026-64827 is a critical-severity vulnerability with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-807.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v4: 9.3
- EPSS exploit prediction: 0% (37th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-807
- Published:
- Last modified:
Description
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
Frequently asked questions
- What is CVE-2026-64827?
- Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
- How severe is CVE-2026-64827?
- CVE-2026-64827 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-64827 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-64827?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-64827 published?
- CVE-2026-64827 was published on 2026-08-03 and last updated on 2026-08-07.
References
- https://karmainsecurity.com/KIS-2026-14
- https://www.teleniasoftware.com/
- https://www.vulncheck.com/advisories/telenia-tvox-authentication-bypass-via-set-env-php
- http://seclists.org/fulldisclosure/2026/Aug/30
Other CWE-807 vulnerabilities
- CVE-2025-13926 — Critical (CVSS 9.8): An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary…
- CVE-2026-32975 — Critical (CVSS 9.8): OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable…
- CVE-2025-12488 — Critical (CVSS 9.8): oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability.…
- CVE-2025-12487 — Critical (CVSS 9.8): oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability.…
- CVE-2025-49827 — Critical (CVSS 9.8): Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through…
- CVE-2025-1126 — Critical (CVSS 9.3): A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management…