Description
A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests.
Published: 2026-03-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Password Reset via Broken Access Control
Action: Immediate Patch
AI Analysis

Impact

A broken access control flaw in the password reset feature of the Cognix Recon Client permits any authenticated user to craft requests that reset the passwords of arbitrary accounts. This weakness, identified as CWE-284, enables an attacker to forcibly take over other users’ accounts, potentially accessing sensitive data or persisting malicious control. As the vulnerability allows the attacker to avoid legitimate authorization steps, it effectively negates the integrity of user credentials and can serve as a vector for broader system compromise.

Affected Systems

The affected system is Tata Consultancy Services’ Cognix Recon Client, specifically version 3.0. Users of this version are susceptible to abuse of the password reset routine, regardless of the user’s role or permissions within the application.

Risk and Exploitability

The CVSS score of 8.1 classifies this flaw as high severity, signifying substantial risk to confidentiality, integrity, and availability. The EPSS score of less than 1% indicates that, overall, exploit attempts are expected to be infrequent at this time, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, the exploit path requires only an authenticated session and the ability to send crafted requests, making it relatively straightforward for internal users or attackers who have compromised credentials. The attack vector is likely intra‑network or through compromised user accounts, exploiting the lack of role or ownership checks during the reset process.

Generated by OpenCVE AI on April 17, 2026 at 12:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch or upgrade to a version that restricts password reset privileges to the account owner.
  • Restrict password reset functionality to authenticated administrators or implement a confirmation workflow that requires ownership verification before resetting a password.
  • Enable logging and monitoring of password reset requests, and investigate any unauthorized or anomalous reset attempts.

Generated by OpenCVE AI on April 17, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Tcs cognix Platform
CPEs cpe:2.3:a:tcs:cognix_platform:3.0:*:*:*:*:*:*:*
Vendors & Products Tcs cognix Platform

Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Tcs
Tcs cognix Recon Client
Vendors & Products Tcs
Tcs cognix Recon Client

Fri, 06 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Description A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests.
References

Subscriptions

Tcs Cognix Platform Cognix Recon Client
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-06T09:54:32.474Z

Reserved: 2026-02-16T00:00:00.000Z

Link: CVE-2026-26417

cve-icon Vulnrichment

Updated: 2026-03-06T09:54:26.500Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-05T19:16:04.680

Modified: 2026-03-10T18:49:41.163

Link: CVE-2026-26417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T13:00:12Z

Weaknesses