
Detailed write-up of CVE-2026-26416, an authorization bypass vulnerability in TCS Cognix Recon Client v3.0 allowing privilege escalation via crafted API requests, including technical classification, affected endpoints, and remediation timeline.
A privilege escalation vulnerability was identified in Tata Consultancy Services (TCS) – Cognix Recon Client v3.0.
The issue allowed authenticated users to elevate privileges across defined role boundaries through manipulation of crafted API requests.
The vulnerability originated from insufficient enforcement within the role-based access control (RBAC) logic, enabling predictable object identifiers to bypass authorization validation mechanisms.
Tata Consultancy Services (TCS)
Cognix Recon Client – Version 3.0
Discoverer: Ahmed Khalid Alsalimi
Disclosure Model: Coordinated Responsible Disclosure with TCS
The vulnerability was responsibly reported to Tata Consultancy Services (TCS).
The vendor acknowledged the finding and worked collaboratively to implement remediation.
TCS implemented enhanced authorization validation and strengthened role verification enforcement mechanisms to prevent manipulation of user-controlled identifiers.
The vulnerability has been validated as remediated in the currently deployed version of the product.