Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-26418 — Documentation of CVE-2026-26418, a missing authentication and authorization vulnerability in TCS Cognix Recon Client v3.0 Web API, including affected endpoints, remediation, and disclosure timeline. | Kitploit
Tools/GitHubGitHub/aksalsalimi/cve-2026-26418
Authentication & AuthorizationVulnerability AnalysisWeb SecurityLearning & EducationCurated Resources
GitHubaksalsalimi/cve-2026-26418

CVE-2026-26418

Documentation of CVE-2026-26418, a missing authentication and authorization vulnerability in TCS Cognix Recon Client v3.0 Web API, including affected endpoints, remediation, and disclosure timeline.

View Repository
5 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-26418

Missing Authentication and Authorization in Web API

Vulnerability Summary

A missing authentication and authorization vulnerability was identified in the Web API layer of Tata Consultancy Services (TCS) – Cognix Recon Client v3.0.

Certain exposed API endpoints did not enforce proper authentication and authorization controls, allowing remote access to application functionality without appropriate validation.


Technical Classification (CWE)

  • CWE-306 – Missing Authentication for Critical Function
  • CWE-862 – Missing Authorization

Affected Endpoints

  • http://clientreconhost/reconciliations/*
  • http://clientreconhost/Scheduler/*
  • http://clientreconhost/DynamicReport/*

Vendor

Tata Consultancy Services (TCS)

Affected Product

Cognix Recon Client – Version 3.0


Disclosure Information

Discoverer: Ahmed Khalid Alsalimi
Disclosure Model: Coordinated Responsible Disclosure with TCS

The vulnerability was responsibly disclosed to Tata Consultancy Services (TCS).
The vendor acknowledged the issue and implemented corrective actions.


Remediation Status

TCS enforced mandatory authentication requirements and strengthened authorization validation across affected API endpoints.

The vulnerability has been validated as remediated in the currently deployed version of the product.


Disclosure Timeline

  • Discovered: January 2026
  • TCS Notified: Coordinated Disclosure
  • TCS implemented remediation on 4 February 2026
  • CVE Assigned: March 2026
  • CVE Published: March 2026
Download Tool