CVE-2026-26417

HIGH

TCS Cognix Recon Client 3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-26417. PoCs published by XiaomingX, aksalsalimi.

AI-analyzed exploit summary This repository provides a detailed technical writeup on CVE-2026-26417, a broken access control vulnerability in TCS Cognix Recon Client v3.0, allowing authenticated users to reset arbitrary passwords via crafted API requests. It includes CWE classifications, affected endpoints, and remediation details.

Description

A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests.

Exploits (2)

github WRITEUP 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-26417

This repository provides a detailed technical writeup on CVE-2026-26417, a broken access control vulnerability in TCS Cognix Recon Client v3.0, allowing authenticated users to reset arbitrary passwords via crafted API requests. It includes CWE classifications, affected endpoints, and remediation details.

Classification
Writeup 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: TCS Cognix Recon Client v3.0
Auth required
Prerequisites: authenticated user access
devstral-2 · analyzed Mar 06, 2026 Full analysis →
nomisec WRITEUP
by aksalsalimi · poc
https://github.com/aksalsalimi/CVE-2026-26417

This repository provides a detailed technical writeup of CVE-2026-26417, a broken access control vulnerability in TCS Cognix Recon Client v3.0, allowing authenticated users to reset arbitrary user passwords via crafted API requests.

Classification
Writeup 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: TCS Cognix Recon Client v3.0
Auth required
Prerequisites: authenticated access to the application
devstral-2 · analyzed Apr 28, 2026 Full analysis →

Scores

CVSS v3 8.1
EPSS 0.0027
EPSS Percentile 19.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
tcs/cognix_platform 3.0
Published Mar 05, 2026
Tracked Since Mar 06, 2026