SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-62646

HIGH · CVSS 7.4 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in Reyrolle 7SR5 versions prior to V2.70, where the session identifier is generated using a weak algorithm, leading to low entropy and predictability. This flaw enables unauthenticated remote attackers to potentially derive valid session tokens, allowing them to bypass authentication mechanisms. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized access.

CVE
CVE-2026-62646
Severity
HIGH
CVSS
7.4
EPSS
0.32%

Original NVD Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.