CVE-2026-23596
Unauthenticated Improper Access Control in management API allows unauthorized service disruption
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →