CVE-2026-22096

CRITICAL

EVbee DC-80 - Missing Authentication for Webserver Endpoints

Title source: rule
STIX 2.1

Description

The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://csirt.divd.nl/DIVD-2026-00001/

Scores

CVSS v4 9.3
EPSS 0.0031
EPSS Percentile 23.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
EVbee/DC-80 < 1.5.1
Published Jul 13, 2026
Tracked Since Jul 13, 2026