CVE-2026-18783
HighPublished
Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES
- Published
- Sep 30, 2026
- Updated
- Sep 30, 2026
- Assigning CNA
- TR-CERT
- Evidence observed
- Oct 2, 2026
Primary CVSS
8.8/ 10High
nvd · CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29.
Sources
Advisory for CVE-2026-18783: missing server-side authentication on TREX MES /api/GetDataJSON3 allows unauthenticated data queries and arbitrary SQL execution.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.