CVE-2026-5794
Received
Received - Intake
Account Lockout Vulnerability in Cryptobox Enables Denial of Service
Publication date: 2026-04-28
Last updated on: 2026-04-28
Assigner: Thales Group
Description
Description
A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| thalesgroup | cryptobox | * |
| thales | cryptobox | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-694 | The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required. |