Description
POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authentication flaw in the FitSoft POS System permits unauthenticated remote attackers to directly log in and control the entire point‑of‑sale interface, potentially altering transaction records, exposing sensitive customer data, and disrupting business operations. The vulnerability is identified as CWE‑306, which allows an attacker to bypass any login requirement.

Affected Systems

The vulnerability affects the FitSoft POS System. No specific version information is provided, so all installations of this product are considered potentially impacted until a vendor‑issued remedy is applied.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity, indicating significant potential damage to confidentiality, integrity, and availability. While the vulnerability is not yet listed in the CISA KEV catalog and no exploitation probability has been published, the lack of authentication still poses a critical risk. The attacker can remotely reach the POS system’s management interface from any network‑connected device, allowing direct control over the point‑of‑sale operations.

Generated by OpenCVE AI on August 12, 2026 at 12:16 UTC.

Remediation

Vendor Solution

Contact the vendor to take remedial measures.


OpenCVE Recommended Actions

  • Contact FitSoft immediately to obtain remediation guidance and apply any vendor‑issued fix or control measures.
  • Configure network‑level controls such as firewall rules or VLAN segmentation to limit inbound access to the POS system’s management interface, reducing the attack surface.
  • Continuously monitor system logs for unauthorized access attempts and configure automated alerts or blocklists to respond to suspicious activity.

Generated by OpenCVE AI on August 12, 2026 at 12:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Fitsoft
Fitsoft pos System
Vendors & Products Fitsoft
Fitsoft pos System

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.
Title FitSoft|POS Sytstem - Missing Authentication
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Fitsoft Pos System
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-08-12T12:33:07.848Z

Reserved: 2026-08-10T11:31:30.793Z

Link: CVE-2026-19426

cve-icon Vulnrichment

Updated: 2026-08-12T12:33:03.024Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T08:17:17.493

Modified: 2026-08-26T16:40:21.650

Link: CVE-2026-19426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:48:51Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function