#VU123323 Improper Authentication in DIRIS A-40 - CVE-2026-2491

 

#VU123323 Improper Authentication in DIRIS A-40 - CVE-2026-2491

Published: February 27, 2026


Vulnerability identifier: #VU123323
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-2491
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
DIRIS A-40
Software vendor:
Socomec

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests within the web API implementation. A remote attacker on the local network can bypass authentication process and gain unauthorized access to the application.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links