Stats Digest Feeds
← Back to all CVEs

CVE-2026-92625

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Sep 16, 2026
Vendor unknown

Description

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous restart cycle, rendering it unavailable.

References