WebSocket API Lacks Rate Limiting Vulnerability in Affected Software
CVE-2026-50176

8.7HIGH

Key Information:

Vendor

Evoke

Vendor
CVE Published:
25 June 2026

What is CVE-2026-50176?

The vulnerability in the WebSocket Application Programming Interface stems from insufficient restrictions on the number of authentication requests. This lack of rate limiting exposes the software to potential denial-of-service attacks and allows attackers to execute brute-force attempts, ultimately jeopardizing user authentication security and system integrity. Organizations using the affected software should implement necessary mitigations to enhance security against these attack vectors.

Affected Version(s)

EVoke CSMS All versions

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khaled Sarieddine and Mohammad Ali Sayed reported this vulnerability to CISA.
.