Description
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.


The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Control iD iDSecure allows an unauthenticated attacker to trigger a null reference exception on the /api/dguardintegration/dguardVersion endpoint. The underlying code dereferences a login state that may be unset and the function is asynchronous and returns void, so the exception is unhandled and can terminate the iDSecure process. The result is a service disruption without affecting data integrity or confidentiality.

Affected Systems

Vulnerable installations are those running Control iD iDSecure versions earlier than 4.8.3.0. The issue is tied to the iDSecure product and is specific to the identified product line.

Risk and Exploitability

The CVSS score of 7.5 indicates a high likelihood of serious impact once triggered, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog and requires no authentication to exercise, meaning any host exposed to the API can be impacted. The attack path involves sending an unauthenticated request to the mentioned endpoint, causing the unhandled exception and process termination.

Generated by OpenCVE AI on September 18, 2026 at 06:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s update that includes the null‑reference guard, i.e., upgrade to version 4.8.3.0 or later.
  • Disable or restrict access to the /api/dguardintegration/dguardVersion endpoint until the patch is deployed, reducing the attack surface for unauthenticated requests.
  • Introduce application monitoring that detects sudden process crashes or abnormal termination events and alerts administrators to investigate promptly.

Generated by OpenCVE AI on September 18, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Controlid
Controlid idsecure
Vendors & Products Controlid
Controlid idsecure

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.
Title Control iD iDSecure Unauthenticated Denial of Service
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Controlid Idsecure
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-09-17T17:35:16.835Z

Reserved: 2026-09-16T15:13:32.979Z

Link: CVE-2026-92626

cve-icon Vulnrichment

Updated: 2026-09-17T17:35:12.899Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T16:17:23.877

Modified: 2026-09-18T19:18:42.907

Link: CVE-2026-92626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:32Z

Weaknesses