CVE Feed

    Dashboard / CVE / CVE-2026-26342

    CVE-2026-26342

    Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the management interface until the token is revoked, enabling unauthorized access to device functions and data.

    Published:Feb 24, 2026
    Last Modified:Apr 16, 2026
    EPS:Feb 24, 2026
    EPSS Score:0.00353
    CVSS Score:9.8

    Affected Products

    Vendor
    Iptime
    Product
    Smart Firmware
    Vendor
    Tattile
    Product
    Anpr Mobile
    Vendor
    Tattile
    Product
    Anpr Mobile Firmware
    Vendor
    Tattile
    Product
    Axle Counter
    Vendor
    Tattile
    Product
    Axle Counter Firmware
    Vendor
    Tattile
    Product
    Basic Mk2
    Vendor
    Tattile
    Product
    Basic Mk2 Firmware
    Vendor
    Tattile
    Product
    Smart+
    Vendor
    Tattile
    Product
    Smart+ Speed
    Vendor
    Tattile
    Product
    Smart+ Traffic Light
    Vendor
    Tattile
    Product
    Smart\+
    Vendor
    Tattile
    Product
    Smart\+ Firmware
    Vendor
    Tattile
    Product
    Smart\+ Speed
    Vendor
    Tattile
    Product
    Smart\+ Speed Firmware
    Vendor
    Tattile
    Product
    Smart\+ Traffic Light
    Vendor
    Tattile
    Product
    Smart\+ Traffic Light Firmware
    Vendor
    Tattile
    Product
    Tolling+
    Vendor
    Tattile
    Product
    Tolling\+
    Vendor
    Tattile
    Product
    Tolling\+ Firmware
    Vendor
    Tattile
    Product
    Vega11
    Vendor
    Tattile
    Product
    Vega11 Firmware
    Vendor
    Tattile
    Product
    Vega33
    Vendor
    Tattile
    Product
    Vega33 Firmware
    Vendor
    Tattile
    Product
    Vega53
    Vendor
    Tattile
    Product
    Vega53 Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High