AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-28148

CRITICAL · CVSS 9.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

An unauthenticated bypass vulnerability exists in Headless Single Sign On versions up to 1.6, allowing attackers to gain unauthorized access to sensitive resources without authentication. This critical flaw, rated 9.8 on the CVSS scale, poses a significant risk to organizations using affected versions, particularly those relying on single sign-on for user authentication. Organizations should prioritize patching or mitigating this vulnerability to prevent potential data breaches and unauthorized access.

CVE
CVE-2026-28148
Severity
CRITICAL
CVSS
9.8
EPSS
0.24%

Original NVD Description

Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.