SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-27844

LOW · CVSS 2.7 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The Controller 6000 and Controller 7000 diagnostic web interface is vulnerable to an uncaught exception that allows authenticated operators to send specific requests, resulting in a temporary denial of service through a controller restart. This issue affects multiple versions of the Command Centre software, specifically those prior to designated patch releases. Organizations using these affected versions should prioritize remediation to prevent potential disruptions in service.

CVE
CVE-2026-27844
Severity
LOW
CVSS
2.7
EPSS
0.23%

Original NVD Description

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service.  Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.