ZeroHour

CVE-2026-18771

niche

Authentication Bypass in TMT Talassoft Industrial Management Software

CVSS 3.1
7.5 high
EPSS
<1%p33
Published
()
Modified
AI analysis

Talassoft Industrial Management Software, developed by Turkey-based TMT Machine Industry and Trade Ltd. Co., contains a missing authentication for critical function flaw (CWE-306) that allows an unauthenticated attacker to bypass authentication. Because the vulnerable function is reachable over the network with no privileges or user interaction required (per the CVSS vector), an attacker can trigger it simply by sending requests to the affected service. The flaw is scored 7.5 (high) with a high availability impact, meaning an attacker who bypasses authentication can gain access to critical management functions and disrupt the system. Only installations running Talassoft Industrial Management Software from V4 before V.16 are affected. There are no reports of exploitation in the wild, no public proof-of-concept, and EPSS currently estimates only a 0.4% probability of exploitation in the next 30 days.

What to do: Upgrade Talassoft Industrial Management Software to V.16 or later, which resolves the missing authentication issue. Until upgraded, restrict network access to the Talassoft service (e.g., firewall or VPN) so it is not reachable by unauthenticated users from untrusted networks. Operators should inventory which sites run affected versions from V4 up to but not including V.16 and verify whether the software is exposed to the internet.

Affected
TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Softwarefrom V4 before V.16
Estimated exposure
nicheunknown — likely limited to hundreds to low thousands of deployments among the vendor's industrial customers, but no public install-base or internet-exposure… — Talassoft is a niche vertical industrial management product from a single Turkish vendor with no published install counts or scan data, so deployments are presumed limited to manufacturing/industrial customers, making any figure a rough…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.