SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19506

HIGH · CVSS 8.1 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A race condition in the `check.jst` file of the RDK-B WebUI allows remote attackers to exploit shared authentication state, potentially leading to unauthorized access through concurrent authentication requests. Organizations using the affected version, `rdkb-2025q4-kirkstone.04.10.26`, should prioritize remediation to mitigate the risk of unauthorized access to their systems. Immediate attention is recommended for those managing devices or services utilizing this version of the RDK-B framework.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19506
Severity
HIGH
CVSS
8.1
EPSS
0.39%

Original NVD Description

Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state.