{"id":"CVE-2026-92625","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-92625","summary":"Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.\n\n\nThe /api/license/restartService endpoint is reachable without authentication and…","details":"Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.\n\n\nThe /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous restart cycle, rendering it unavailable.","published":"2026-09-16T16:17:23.760","modified":"2026-09-17T18:17:14.560","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tenable.com/security/research/tra-2026-56"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T18:17:14.560"}}