CVE-2026-27546
Received Received - Intake

Authentication Bypass in Account Log Function

Vulnerability report for CVE-2026-27546, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: CERT VDE

Description

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-09-16
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
pepperl_fuchs ice2 to 1.7.4 (exc)
pepperl_fuchs ice3 to 1.7.4 (exc)
phoenix_contact iol_ma8_eip_di8 to 1.7.4 (exc)
phoenix_contact iol_ma8_pn_di8 to 1.7.4 (exc)
carlo_gavazzi_automation yl212 to 1.7.4 (exc)
carlo_gavazzi_automation yn115 to 1.7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27546. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart