Unauthorized Access Vulnerability in CGI Endpoints of MyApp by MyCompany
CVE-2026-22905

7.5HIGH

Key Information:

Vendor

Wago

Vendor
CVE Published:
9 February 2026

What is CVE-2026-22905?

An unauthenticated remote attacker can exploit this vulnerability by bypassing authentication through inadequate URI validation. By leveraging path traversal sequences, such as /js/../cgi-bin/post.cgi, attackers gain unauthorized access to sensitive CGI endpoints and potentially download configuration files, thereby compromising the security of MyApp.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

0852-1322 0.0.0 <= 2.64

0852-1322 2.64

0852-1328 0.0.0 <= 2.64

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diconium
.