Description
Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass.

This issue affects Talassoft Industrial Management Software: from V4 before V.16.
Published: 2026-09-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allowing unauthorized execution of critical functions.
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authentication for a critical function, classified as CWE‑306. It allows an attacker who can reach the affected component to execute that function without providing credentials, potentially enabling full control over critical industrial processes or data. The impact is the loss of confidentiality, integrity, and availability of the system’s managed assets because the bypass removes the guard that normally protects sensitive operations.

Affected Systems

This issue affects Talassoft Industrial Management Software produced by TMT Machine Industry and Trade Ltd. Co. Versions from V4 up to, but not including, V16 are vulnerable. No other versions are explicitly listed as affected.

Risk and Exploitability

The CVSS v3.1 score of 7.5 indicates a high severity, while the EPSS score is not publicly available. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of analysis. The likely attack vector is remote, as the function can be accessed over the network. An attacker with network access to the software can call the vulnerable endpoint and bypass authentication, potentially achieving privilege escalation or full control of the industrial environment.

Generated by OpenCVE AI on September 1, 2026 at 16:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Talassoft Industrial Management Software to version 16 or newer to remove the missing authentication flaw.
  • If an immediate upgrade is not feasible, block or restrict network traffic to the critical function’s endpoint using firewalls, access control lists, or application layer gateways.
  • Enable comprehensive logging and monitoring on the system to detect unauthorized attempts to invoke the critical function and alert security personnel promptly.

Generated by OpenCVE AI on September 1, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Tmt Machine
Tmt Machine talassoft Industrial Management Software
Vendors & Products Tmt Machine
Tmt Machine talassoft Industrial Management Software

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.
Title Missing Authentication for Critical Function in TMT Machine's Talassoft Industrial Management Software
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Tmt Machine Talassoft Industrial Management Software
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-01T15:52:31.842Z

Reserved: 2026-08-04T07:17:13.652Z

Link: CVE-2026-18771

cve-icon Vulnrichment

Updated: 2026-09-01T15:52:23.051Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T15:17:13.060

Modified: 2026-09-01T21:10:38.413

Link: CVE-2026-18771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T21:39:30Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function