CVE-2026-92625
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Sep 16, 2026
Vendor
unknown
Description
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous restart cycle, rendering it unavailable.