CVE-2026-26418

HIGH

TCS Cognix Recon Client 3.0 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-26418. PoCs published by XiaomingX, aksalsalimi.

AI-analyzed exploit summary This repository provides a detailed technical writeup on CVE-2026-26418, a missing authentication and authorization vulnerability in TCS Cognix Recon Client v3.0. It includes affected endpoints, CWE classifications, and remediation details.

Description

Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network.

Exploits (2)

github WRITEUP 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-26418

This repository provides a detailed technical writeup on CVE-2026-26418, a missing authentication and authorization vulnerability in TCS Cognix Recon Client v3.0. It includes affected endpoints, CWE classifications, and remediation details.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: TCS Cognix Recon Client v3.0
No auth needed
Prerequisites: Network access to the affected endpoints
devstral-2 · analyzed Mar 06, 2026 Full analysis →
nomisec WRITEUP
by aksalsalimi · poc
https://github.com/aksalsalimi/CVE-2026-26418

This repository provides a detailed technical writeup on CVE-2026-26418, a missing authentication and authorization vulnerability in TCS Cognix Recon Client v3.0. It includes affected endpoints, CWE classifications, and remediation details.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: TCS Cognix Recon Client v3.0
No auth needed
Prerequisites: network access to the affected endpoints
devstral-2 · analyzed Apr 28, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0041
EPSS Percentile 32.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
tcs/cognix_platform 3.0
Published Mar 05, 2026
Tracked Since Mar 06, 2026