Session Management Vulnerability in NT-ware uniFLOW Online
CVE-2026-92378

4.1MEDIUM

Key Information:

Vendor

Nt-ware

Vendor
CVE Published:
23 September 2026

What is CVE-2026-92378?

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. During specific timing conditions in Service Offline Emergency Mode, a previously authenticated session may not terminate correctly upon logout. This flaw could allow a subsequent user to gain unauthorized limited access to device functionality as they may be authenticated as the previous user. The issue underscores the importance of robust session management protocols to ensure that sensitive information remains secure.

Affected Version(s)

uniFLOW Online Web Application 0 <= 2026.2

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.