CVE-2026-64827
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.48%
- CWE
- CWE-807
- Published
- 2026-08-03
- Last modified
- 2026-08-07
Affected products
- Telenia Software TVox
- Telenia Software TVox
Weakness type
Related vulnerabilities
- CVE-2026-88004 — Traefik entrypoint header-name sanitization bypassed via request trailers
- CVE-2026-87479 — Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a...
- CVE-2026-82533 — DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
- CVE-2026-66768 — Improper Access Control in SAP NetWeaver (SAP GUI for Java)
- CVE-2026-85602 — Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
- CVE-2026-63041 — Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
- CVE-2026-54730 — authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView
- CVE-2026-53789 — rsync < 3.5.0 Arbitrary File Deletion via Malicious File List