CVE-2026-16876
Received Received - Intake

Authentication Bypass in NEC UNIVERGE IX-R/IX-V WebGUI

Vulnerability report for CVE-2026-16876, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: NEC Corporation

Description

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
nec univerge_ix-r From 1.1 (inc) to 1.3 (inc)
nec univerge_ix-v From 1.1 (inc) to 1.3 (inc)
nec univerge_ix-r From 1.4.21 (inc) to 1.4.28 (inc)
nec univerge_ix-v From 1.4.21 (inc) to 1.4.28 (inc)
nec univerge_ix-r *
nec univerge_ix-v *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-16876 is an authentication bypass vulnerability in the WebGUI of NEC's UNIVERGE IX-R/IX-V series network devices. It allows an attacker to bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device over the internet.

Detection Guidance

To detect this vulnerability, monitor network traffic for unusual WebGUI message tampering or CLI command execution attempts. Check device logs for unauthorized access or command execution. Inspect network devices running UNIVERGE IX-R/IX-V series firmware versions between Ver1.1 to Ver1.3, Ver1.4.21 to Ver1.4.28, or Ver1.5.23.

Impact Analysis

This vulnerability could allow unauthorized access to network devices, enabling attackers to execute malicious commands, disrupt network operations, or gain control over the device. It poses a significant risk to network security and stability.

Compliance Impact

This vulnerability could lead to unauthorized access and execution of commands on network devices, potentially compromising data confidentiality and integrity. For GDPR, it may result in unauthorized data access or processing, violating principles of lawfulness and security. For HIPAA, it could allow unauthorized access to protected health information, violating safeguards for confidentiality and integrity.

Mitigation Strategies

Immediately update affected devices to the latest firmware version or disable the WebGUI interface to prevent exploitation. Ensure network segmentation to limit exposure of vulnerable devices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16876. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart