Authentication Bypass Vulnerability in Vendor's Product
CVE-2026-27546

9.8CRITICAL

What is CVE-2026-27546?

An authentication bypass vulnerability exists in the _account_log function, allowing unauthenticated remote attackers to gain admin access. This flaw can be exploited even in well-configured accounts, posing a significant risk to the integrity of the affected product. Proper security measures should be enacted to patch this vulnerability and protect against unauthorized administrative actions.

Affected Version(s)

ICE2-8IOL-G65L-V1D 1.0.0 < 1.7.4

ICE2-8IOL-K45P-RJ45 1.0.0 < 1.7.4

ICE2-8IOL-K45S-RJ45 1.0.0 < 1.7.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Quagliarella from Nozomi Networks
Luca Borzacchiello from Nozomi Networks
.