Critical severity9.8NVD Advisory· Published Aug 3, 2026· Updated Sep 9, 2026
CVE-2026-64827
CVE-2026-64827
Description
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
Affected products
1- Range: 26.5.3 and prior 26.x, 24.9.21 and prior 24.x
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.