Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92626— Control iD iDSecure Unauthenticated Denial of Service

Quick assessment

Affected
Control iD iDSecure
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Control iD iDSecure 4.8.3.0 之前的版本存在一个未经身份验证的拒绝服务(DoS)漏洞。 端点在对 DGuard 集成登录状态进行解引用时,如果该状态未被设置,就会抛出未处理的空引用异常。由于该异常是从一个返回值为 的异步方法中抛出的,调用方无法捕获或观察到该异常,从而导致 iDSecure 进程终止。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1515
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92626

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Control iD iDSecure Unauthenticated Denial of Service
Source: CVE Program / CVE List V5
Vulnerability Description
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Control iD iDSecure 0 ~ 4.8.3.0 -

II. Public POCs for CVE-2026-92626

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92626

登录查看更多情报信息。

Other References for CVE-2026-92626 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92626

No comments yet


Leave a comment