← Back to browse · API

CVE-2022-26833

Severity
CRITICAL
CVSS
9.4
EPSS
0.37177
Risk score
50.61
CISA KEV
No
PoC
No
Published
2022-05-25
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2022-31383, GHSA-Q479-F3R3-9XQ7
Products
Open Automation Software:OAS Platform V16.00.0121
Sources
euvd EUVD-2022-31383

Description

An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.

References