Improper authentication in Gaia - CVE-2026-16232
Published: July 23, 2026
Gaia
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper authentication in SmartConsole login using application token in Management when handling login requests. A remote attacker can send a specially crafted login request to bypass authentication.
The vulnerability is being actively exploited in the wild.