An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSO Component Allows Password‑Free Authentication as Any User |
Tue, 08 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSO Component Allows Password‑Free Authentication as Any User |
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Tue, 08 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-09-08T00:00:00.000Z
Updated: 2026-09-08T15:34:16.417Z
Reserved: 2026-08-25T00:00:00.000Z
Link: CVE-2026-79576
Updated: 2026-09-08T15:34:11.346Z
Status : Deferred
Published: 2026-09-08T15:18:48.417
Modified: 2026-09-09T16:04:24.933
Link: CVE-2026-79576
No data.