CVE-2026-92378
Received Received - Intake

Session Retention in uniFLOW Online Legacy UI

Vulnerability report for CVE-2026-92378, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Canon_EMEA

Description

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nt-ware uniflow_online 2026.2
nt-ware uniflow_online 2026.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a session management flaw in NT-ware uniFLOW Online's Legacy UI Reduced Function Login feature. Under rare timing conditions during Service Offline Emergency Mode, a previous user's authenticated session may persist after logout. If another user then accesses the device via Reduced Function Login within a short window before the session auto-clears, they could be authenticated as the prior user and gain unauthorized limited access to device functions.

Detection Guidance

This vulnerability requires specific timing conditions and cannot be reliably detected through standard commands. Monitor for unusual session persistence in uniFLOW Online 2026.2 during Reduced Function Login in emergency mode. Check logs for multiple users accessing the same session after logout.

Impact Analysis

The impact is limited but could allow an unauthorized user to access basic device functions (like copying) under specific emergency-mode conditions. This requires a precise sequence of events including a delayed login attempt, session timeout, and another user accessing Reduced Function Login quickly. No active exploitation has been reported.

Mitigation Strategies

Upgrade to uniFLOW Online 2026.3 or later, as the vendor has globally deployed the fix. No manual action is required. If upgrading is not possible, restrict access to Reduced Function Login during emergency mode until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92378. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart