
Documentation of CVE-2026-26418, a missing authentication and authorization vulnerability in TCS Cognix Recon Client v3.0 Web API, including affected endpoints, remediation, and disclosure timeline.
A missing authentication and authorization vulnerability was identified in the Web API layer of Tata Consultancy Services (TCS) – Cognix Recon Client v3.0.
Certain exposed API endpoints did not enforce proper authentication and authorization controls, allowing remote access to application functionality without appropriate validation.
Tata Consultancy Services (TCS)
Cognix Recon Client – Version 3.0
Discoverer: Ahmed Khalid Alsalimi
Disclosure Model: Coordinated Responsible Disclosure with TCS
The vulnerability was responsibly disclosed to Tata Consultancy Services (TCS).
The vendor acknowledged the issue and implemented corrective actions.
TCS enforced mandatory authentication requirements and strengthened authorization validation across affected API endpoints.
The vulnerability has been validated as remediated in the currently deployed version of the product.