CVE-2026-5057
Last modified
CVE-2026-5057 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon.
Description
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-29041.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ATEN | Unizon | 2.6.253.001 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-5057?
How severe is CVE-2026-5057?
How do I fix CVE-2026-5057?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50564Fission is an open-source, Kubernetes-native serverless fram…9.9
- CVE-2026-50565Fission is an open-source, Kubernetes-native serverless fram…4.9
- CVE-2026-50566Fission is an open-source, Kubernetes-native serverless fram…9.9
- CVE-2026-50567Fission is an open-source, Kubernetes-native serverless fram…7.7
- CVE-2026-50568Fission is an open-source, Kubernetes-native serverless fram…3.6
- CVE-2026-50569Fission is an open-source, Kubernetes-native serverless fram…4.3
- CVE-2026-50570Fission is an open-source, Kubernetes-native serverless fram…8.5
- CVE-2026-50573pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnp…8.1
- CVE-2026-50574yt-dlp is a command-line audio/video downloader. Prior to 20…9.6
- CVE-2026-5058aws-mcp-server Command Injection Remote Code Execution Vulne…9.8
- CVE-2026-50589In OpenStack Ironic 32 before 37.0.0, an unauthenticated mal…7.5
- CVE-2026-5059aws-mcp-server AWS CLI Command Injection Remote Code Executi…9.8
Are you affected by CVE-2026-5057?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
