Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/aksalsalimi/cve-2026-26416
Vulnerability AnalysisExploitationWeb SecurityPenetration TestingLearning & Education
GitHubaksalsalimi/cve-2026-26416

CVE-2026-26416

Detailed write-up of CVE-2026-26416, an authorization bypass vulnerability in TCS Cognix Recon Client v3.0 allowing privilege escalation via crafted API requests, including technical classification, affected endpoints, and remediation timeline.

View Repository
5 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-26416

Authorization Bypass Vulnerability Leading to Privilege Escalation

Vulnerability Summary

A privilege escalation vulnerability was identified in Tata Consultancy Services (TCS) – Cognix Recon Client v3.0.
The issue allowed authenticated users to elevate privileges across defined role boundaries through manipulation of crafted API requests.

The vulnerability originated from insufficient enforcement within the role-based access control (RBAC) logic, enabling predictable object identifiers to bypass authorization validation mechanisms.


Technical Classification (CWE)

  • CWE-269 – Improper Privilege Management
  • CWE-863 – Incorrect Authorization
  • CWE-639 – Authorization Bypass Through User-Controlled Key

Affected Endpoints

  • http://clientreconhost/emp_recon/Authorization/users/getUserRoles

Vendor

Tata Consultancy Services (TCS)

Affected Product

Cognix Recon Client – Version 3.0


Disclosure Information

Discoverer: Ahmed Khalid Alsalimi
Disclosure Model: Coordinated Responsible Disclosure with TCS

The vulnerability was responsibly reported to Tata Consultancy Services (TCS).
The vendor acknowledged the finding and worked collaboratively to implement remediation.


Remediation Status

TCS implemented enhanced authorization validation and strengthened role verification enforcement mechanisms to prevent manipulation of user-controlled identifiers.

The vulnerability has been validated as remediated in the currently deployed version of the product.


Disclosure Timeline

  • Discovered: January 2026
  • TCS Notified: Coordinated Disclosure
  • TCS implemented remediation on 4 February 2026
  • CVE Assigned: March 2026
  • CVE Published: March 2026
Download Tool