CVE-2026-16876CWE-306

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V

Critical · published September 7, 2026

CVSS v4.0
9.3
EPSS
In the wild
Unconfirmed
What it is

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.

The record
Technical detail
CVSS v4.0
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-306 · Missing Authentication for Critical Function
Published
2026-09-07T00:48Z
Timeline
  • 07 SEP 00:48Z
    An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V
    cvelistv5