VYPR
Unrated severityNVD Advisory· Published Sep 23, 2026

uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login

CVE-2026-92378

Description

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.