CVE-2026-92378

Summary

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.

Affected Software

VendorProductVersion RangeStatus
NT-wareuniFLOW Online0 <= 2026.2affected

Weaknesses

  • CWE-613: CWE-613 Insufficient session expiration

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References