Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-26417 — Documentation of a broken access control vulnerability in TCS Cognix Recon Client v3.0, detailing CWE-862/639, affected endpoints, and remediation timeline. | Kitploit
Tools/GitHubGitHub/aksalsalimi/cve-2026-26417
Vulnerability AnalysisWeb SecurityAuthenticationLearning & EducationCurated Resources
GitHubaksalsalimi/cve-2026-26417

CVE-2026-26417

Documentation of a broken access control vulnerability in TCS Cognix Recon Client v3.0, detailing CWE-862/639, affected endpoints, and remediation timeline.

View Repository
56 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-26417

Broken Access Control in Password Reset Functionality

Vulnerability Summary

A broken access control vulnerability was identified in Tata Consultancy Services (TCS) – Cognix Recon Client v3.0.

The issue allowed authenticated users to reset passwords of arbitrary user accounts by submitting crafted API requests without proper authorization validation.

The vulnerability resulted from insufficient ownership verification and missing authorization checks within the password reset workflow.


Technical Classification (CWE)

  • CWE-862 – Missing Authorization
  • CWE-639 – Authorization Bypass Through User-Controlled Key

Affected Endpoints

  • http://clientreconhost/trapeze-client/pwdMgmnt/resetPassword

Vendor

Tata Consultancy Services (TCS)

Affected Product

Cognix Recon Client – Version 3.0


Disclosure Information

Discoverer: Ahmed Khalid Alsalimi
Disclosure Model: Coordinated Responsible Disclosure with TCS

The vulnerability was responsibly disclosed to Tata Consultancy Services (TCS).
The vendor acknowledged the finding and implemented corrective measures.


Remediation Status

TCS implemented strict authorization and ownership validation controls within the password reset functionality.

The vulnerability has been validated as remediated in the currently deployed version of the product.


Disclosure Timeline

  • Discovered: January 2026
  • TCS Notified: Coordinated Disclosure
  • TCS implemented remediation on 4 February 2026
  • CVE Assigned: March 2026
  • CVE Published: March 2026
Download Tool