CVE-2026-26416

HIGH

TCS Cognix Recon Client 3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-26416. PoCs published by XiaomingX, aksalsalimi.

AI-analyzed exploit summary This repository provides a detailed technical writeup of CVE-2026-26416, an authorization bypass vulnerability in TCS Cognix Recon Client v3.0, leading to privilege escalation. It includes CWE classifications, affected endpoints, and remediation details.

Description

An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate privileges across role boundaries via crafted requests.

Exploits (2)

github WRITEUP 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-26416

This repository provides a detailed technical writeup of CVE-2026-26416, an authorization bypass vulnerability in TCS Cognix Recon Client v3.0, leading to privilege escalation. It includes CWE classifications, affected endpoints, and remediation details.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: TCS Cognix Recon Client v3.0
Auth required
Prerequisites: authenticated user access
devstral-2 · analyzed Mar 06, 2026 Full analysis →
nomisec WRITEUP
by aksalsalimi · poc
https://github.com/aksalsalimi/CVE-2026-26416

This repository provides a detailed technical analysis of CVE-2026-26416, an authorization bypass vulnerability in TCS Cognix Recon Client v3.0, including affected endpoints, CWE classifications, and remediation details.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: TCS Cognix Recon Client v3.0
Auth required
Prerequisites: authenticated user access
devstral-2 · analyzed Apr 28, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
tcs/cognix_platform 3.0
Published Mar 05, 2026
Tracked Since Mar 06, 2026