Unrated severityNVD Advisory· Published Aug 3, 2026· Updated Aug 3, 2026
Telenia TVox 26.5.3 Authentication Bypass via set_env.php
CVE-2026-64827
Description
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
Affected products
1- Range: <=26.5.3, <=24.9.21
Patches
Vulnerability mechanics
References
3- karmainsecurity.com/KIS-2026-14mitretechnical-descriptionexploit
- www.vulncheck.com/advisories/telenia-tvox-authentication-bypass-via-set-env-phpmitrethird-party-advisory
- www.teleniasoftware.commitreproduct
News mentions
0No linked articles in our index yet.