Critical severity9.8NVD Advisory· Published Feb 24, 2026· Updated Jun 17, 2026
CVE-2026-26342
CVE-2026-26342
Description
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the management interface until the token is revoked, enabling unauthorized access to device functions and data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- Range: 0
- Tattile s.r.l./Smart+ Traffic Lightv5Range: 0
- Range: 0
0+ 1 more
- (no CPE)range: 0
- (no CPE)range: 0
- cpe:2.3:o:tattile:smart\+_speed_firmware:*:*:*:*:*:*:*:*Range: <=1.181.5
- cpe:2.3:o:tattile:smart\+_traffic_light_firmware:*:*:*:*:*:*:*:*Range: <=1.181.5
- cpe:2.3:o:tattile:axle_counter_firmware:*:*:*:*:*:*:*:*Range: <=1.181.5
Patches
Vulnerability mechanics
References
3- www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5976.phpnvdExploitVendor Advisory
- www.vulncheck.com/advisories/tattile-smart-vega-basic-insufficient-session-token-expirationnvdVDB EntryVendor Advisory
- www.tattile.comnvdProduct
News mentions
0No linked articles in our index yet.