Authorization Bypass in Cisco BroadWorks CommPilot Application Software
CVE-2026-76438

6.5MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-76438?

A vulnerability exists in the web-based management interface of Cisco BroadWorks CommPilot Application Software, which could be exploited by an authenticated remote attacker with low privileges. This flaw stems from inadequate authorization checks, allowing attackers to send specially crafted HTTP requests. If successfully exploited, the attacker could manipulate configurations on designated pages, potentially leading to unauthorized changes within the application.

Affected Version(s)

Cisco BroadWorks 22.0 ap347303

Cisco BroadWorks 22.0

Cisco BroadWorks 24.0 ap374691

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.