CVE-2026-92626

Summary

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.

The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.

Affected Software

VendorProductVersion RangeStatus
Control iDiDSecure0 < 4.8.3.0affected

Weaknesses

  • CWE-476: CWE-476 NULL pointer dereference

References