CRITICALVulnerability
CVE-2026-64827
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
Properties
- severity
- CRITICAL
- score
- 9.8
- cve_id
- CVE-2026-64827
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-03T14:16:27.630
- last_modified
- 2026-08-07T06:16:57.180
Related Entities (2)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Reliance on Untrusted Inputs in a Security Decision
Explore deeper with Ninja Signal's threat intelligence graph