CVE-2026-5794
A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
- EPSS probability
- 0.26%
- CWE
- CWE-694
- Published
- 2026-04-28
- Last modified
- 2026-04-29
Affected products
- Ercom Cryptobox
- Ercom Cryptobox
Weakness type
Related vulnerabilities
- CVE-2026-71327 — Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
- CVE-2026-57024 — Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
- CVE-2025-13609 — Keylime: keylime: registrar allows identity takeover via duplicate uuid registration
- CVE-2025-59048 — OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
- CVE-2024-41146 — Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller...
- CVE-2022-23721 — PingID integration for Windows login duplicate username collision.
- CVE-2023-20100 — Cisco IOS XE Software for Wireless LAN Controllers CAPWAP Join Denial of Service Vulnerability
- CVE-2021-3436 — BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known