SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-5923

MEDIUM · CVSS 6 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability allows an attacker to exploit a stolen cookie to modify the contents of an IP phone's webpage, potentially leading to unauthorized access or manipulation of device settings. Organizations utilizing affected IP phone systems should prioritize this issue to prevent potential security breaches and ensure the integrity of their communication devices. Immediate action is recommended for those managing networked telephony systems to mitigate risks associated with this vulnerability.

CVE
CVE-2026-5923
Severity
MEDIUM
CVSS
6
EPSS
0.14%

Original NVD Description

Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.