OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-27546

CRITICAL · CVSS 9.8 EPSS 1.02% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

An authentication bypass vulnerability exists in the _account_log function, allowing unauthenticated remote attackers to gain administrative access to affected systems, regardless of account configurations. This critical flaw poses a significant risk to the integrity and security of the system, making it imperative for organizations using the affected products to prioritize immediate remediation efforts. All administrators and security teams should assess their systems for exposure and apply necessary patches or mitigations without delay.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-27546
Severity
CRITICAL
CVSS
9.8
EPSS
1.02%

Original NVD Description

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.