#VU123323 Improper Authentication in DIRIS A-40 - CVE-2026-2491
Published: February 27, 2026
Vulnerability identifier: #VU123323
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-2491
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
DIRIS A-40
DIRIS A-40
Software vendor:
Socomec
Socomec
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests within the web API implementation. A remote attacker on the local network can bypass authentication process and gain unauthorized access to the application.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.