{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-16876", "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282", "state": "PUBLISHED", "assignerShortName": "NEC", "dateReserved": "2026-07-24T04:35:25.244Z", "datePublished": "2026-09-07T00:48:01.015Z", "dateUpdated": "2026-09-07T00:48:01.015Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282", "shortName": "NEC", "dateUpdated": "2026-09-07T00:48:01.015Z" }, "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-306", "description": "CWE-306: Missing Authentication for Critical Function", "type": "CWE" } ] } ], "affected": [ { "vendor": "NEC Corporation", "product": "UNIVERGE IX-R/IX-V", "versions": [ { "status": "affected", "version": "All versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23" } ], "defaultStatus": "unknown" } ], "descriptions": [ { "lang": "en", "value": "An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet." } ] } ], "references": [ { "url": "https://jpn.nec.com/security-info/secinfo/nv26-005_en.html" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "HIGH", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "LOW", "subAvailabilityImpact": "NONE", "version": "4.0", "baseSeverity": "CRITICAL", "baseScore": 9.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N" } } ], "credits": [ { "lang": "en", "value": "Kojiro Enokida of Sophos Ltd.", "user": "00000000-0000-4000-9000-000000000000", "type": "reporter" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 0.2.0" } } } }