{"api_version":"1","generated_at":"2026-09-17T05:11:54+00:00","cve":"CVE-2026-92626","urls":{"html":"https://cve.report/CVE-2026-92626","api":"https://cve.report/api/cve/CVE-2026-92626.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-92626","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-92626"},"summary":{"title":"Control iD iDSecure Unauthenticated Denial of Service","description":"Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.\n\n\nThe /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.","state":"PUBLISHED","assigner":"tenable","published_at":"2026-09-16 16:17:23","updated_at":"2026-09-16 16:17:23"},"problem_types":["CWE-476","CWE-476 CWE-476 NULL pointer dereference"],"metrics":[{"version":"3.1","source":"vulnreport@tenable.com","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://www.tenable.com/security/research/tra-2026-56","name":"https://www.tenable.com/security/research/tra-2026-56","refsource":"vulnreport@tenable.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-92626","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92626","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Control iD","product":"iDSecure","version":"affected 4.8.3.0 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"iDSecure","vendor":"Control iD","versions":[{"lessThan":"4.8.3.0","status":"affected","version":"0","versionType":"custom"}]}],"datePublic":"2026-09-16T15:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Control iD iDSecure versions <span>prior to&nbsp;</span>4.8.3.0 are affected by an unauthenticated&nbsp;Denial of Service.<div><br></div><div>The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.</div>"}],"value":"Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.\n\n\nThe /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-476","description":"CWE-476 NULL pointer dereference","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T15:23:21.834Z","orgId":"5ac1ecc2-367a-4d16-a0b2-35d495ddd0be","shortName":"tenable"},"references":[{"url":"https://www.tenable.com/security/research/tra-2026-56"}],"source":{"discovery":"UNKNOWN"},"title":"Control iD iDSecure Unauthenticated Denial of Service","x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"5ac1ecc2-367a-4d16-a0b2-35d495ddd0be","assignerShortName":"tenable","cveId":"CVE-2026-92626","datePublished":"2026-09-16T15:23:21.834Z","dateReserved":"2026-09-16T15:13:32.979Z","dateUpdated":"2026-09-16T15:23:21.834Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 16:17:23","lastModifiedDate":"2026-09-16 16:17:23","problem_types":["CWE-476","CWE-476 CWE-476 NULL pointer dereference"],"metrics":{"cvssMetricV31":[{"source":"vulnreport@tenable.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"92626","Ordinal":"1","Title":"Control iD iDSecure Unauthenticated Denial of Service","CVE":"CVE-2026-92626","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"92626","Ordinal":"1","NoteData":"Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.\n\n\nThe /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.","Type":"Description","Title":"Control iD iDSecure Unauthenticated Denial of Service"}]}}}