CVE-2026-26341
Last modified
CVE-2026-26341 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.. EPSS estimates a 2.66% chance of exploitation in the next 30 days.
Description
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tattile | Smart\+ Firmware | <= 1.181.5 |
| Tattile | Tolling\+ Firmware | <= 1.181.5 |
| Tattile | Smart\+ Speed Firmware | <= 1.181.5 |
| Tattile | Smart\+ Traffic Light Firmware | <= 1.181.5 |
| Tattile | Axle Counter Firmware | <= 1.181.5 |
| Tattile | Vega53 Firmware | <= 1.181.5 |
| Tattile | Vega33 Firmware | <= 1.181.5 |
| Tattile | Vega11 Firmware | <= 1.181.5 |
| Tattile | Basic Mk2 Firmware | <= 1.181.5 |
| Tattile | Anpr Mobile Firmware | <= 1.181.5 |
References
- https://www.tattile.com/Product
- https://www.vulncheck.com/advisories/tattile-smart-vega-basic-default-credentialsThird Party Advisory, VDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5977.phpExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-26341?
How severe is CVE-2026-26341?
How do I fix CVE-2026-26341?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26336Hyland Alfresco allows unauthenticated attackers to read arb…8.7
- CVE-2026-26337Hyland Alfresco Transformation Service allows unauthenticate…8.8
- CVE-2026-26338Hyland Alfresco Transformation Service allows unauthenticate…9.8
- CVE-2026-26339Hyland Alfresco Transformation Service allows unauthenticate…9.8
- CVE-2026-2634Malicious scripts could cause desynchronization between the …9.8
- CVE-2026-26340Tattile Smart+, Vega, and Basic device families firmware ver…7.5
- CVE-2026-26342Tattile Smart+, Vega, and Basic device families firmware ver…9.8
- CVE-2026-26345SPIP before 4.4.8 contains a stored cross-site scripting (XS…8.6
- CVE-2026-26348Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-26349Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-2635MLflow Use of Default Password Authentication Bypass Vulnera…9.8
- CVE-2026-26351GetSimpleCMS Community Edition (CE) versions prior to 3.3.22…4.8
Are you affected by CVE-2026-26341?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
