TenableCVE-2026-92626
Tenable iDSecure: denial of service
High7.5CVE-2026-92626 · Published Sep 16, 2026 · updated Sep 18, 2026
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| iDSecure Product | < 4.8.3.0 | 4.8.3.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-476
More Tenable advisories
All Tenable| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Tenable iDSecure: denial of service | High7.5 | 4.8.3.0 |
| Sep 16 | Tenable Scada-LTS: remote code execution | High8.8 | No fix yet |
| Sep 16 | Tenable Scada-LTS: SQL injection | Medium6.5 | No fix yet |
| Sep 16 | Tenable Scada-LTS: improper access control | High8.8 | No fix yet |
| Aug 31 | Tenable Kubio AI Website Builder: improper input validation | Medium6.9 | 2.9.1 |
| Aug 28 | Tenable Loops & Logic: cross-site scripting | Medium6.5 | No fix yet |