Description
A session management
vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware
uniFLOW Online. Under specific timing conditions during Service Offline
Emergency Mode, a previously authenticated session may be retained after
logout, which could allow a subsequent user to be authenticated as the previous
user and gain unauthorised limited access to device functionality.
Published: 2026-09-23
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Session Retention Unauthorized Access
Action: Mitigate
AI Analysis

Impact

A session management flaw in the Legacy UI Reduced Function Login of NT‑ware uniFLOW Online allows a previously authenticated session to be retained after logout when specific timing conditions occur during Service Offline Emergency Mode. As a result, a different user can be authenticated as the previous user, gaining unauthorized but limited access to device functionality. The weakness is classified as user impersonation and session fixation (CWE‑613).

Affected Systems

The fault affects NT‑ware uniFLOW Online. No specific impacted version numbers are supplied, but all deployments that enable the Legacy UI Reduced Function Login and Service Offline Emergency Mode are potentially vulnerable.

Risk and Exploitability

The CVSS score is 4.1 and the EPSS score is less than 1%, indicating moderate severity and low exploitation probability. The vulnerability is not listed in CISA KEV. The likely attack vector is a user interaction with the web interface during the narrow timing window of Service Offline Emergency Mode; an attacker can reuse a session cookie after logout to impersonate a former user. Given the limited scope of accessible functions, the impact is confined to a small subset of device controls.

Generated by OpenCVE AI on September 23, 2026 at 15:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or avoid using Service Offline Emergency Mode unless it is essential to your operations.
  • Configure the web application to enforce immediate session invalidation on logout and enforce a strict session timeout policy.
  • Apply network segmentation to isolate the device from critical infrastructure, limiting the potential impact.

Generated by OpenCVE AI on September 23, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.
Title uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 4.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Canon_EMEA

Published:

Updated: 2026-09-23T14:49:17.637Z

Reserved: 2026-09-16T07:22:01.696Z

Link: CVE-2026-92378

cve-icon Vulnrichment

Updated: 2026-09-23T14:48:40.687Z

cve-icon NVD

Status : Received

Published: 2026-09-23T08:17:14.237

Modified: 2026-09-23T15:17:29.417

Link: CVE-2026-92378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:30:07Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration