{"id":"CVE-2026-71187","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-71187","summary":"The Ebyte device relies on client side authentication logic that can be \nreproduced by unauthenticated users. An attacker may generate valid \nauthentication requests and bypass authentication…","details":"The Ebyte device relies on client side authentication logic that can be \nreproduced by unauthenticated users. An attacker may generate valid \nauthentication requests and bypass authentication to obtain \nadministrative access to the device.","published":"2026-08-28T00:18:09.150","modified":"2026-08-28T00:18:09.150","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"},{"type":"WEB","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T00:18:09.150"}}