CVE-2026-18771
nicheAuthentication Bypass in TMT Talassoft Industrial Management Software
Talassoft Industrial Management Software, developed by Turkey-based TMT Machine Industry and Trade Ltd. Co., contains a missing authentication for critical function flaw (CWE-306) that allows an unauthenticated attacker to bypass authentication. Because the vulnerable function is reachable over the network with no privileges or user interaction required (per the CVSS vector), an attacker can trigger it simply by sending requests to the affected service. The flaw is scored 7.5 (high) with a high availability impact, meaning an attacker who bypasses authentication can gain access to critical management functions and disrupt the system. Only installations running Talassoft Industrial Management Software from V4 before V.16 are affected. There are no reports of exploitation in the wild, no public proof-of-concept, and EPSS currently estimates only a 0.4% probability of exploitation in the next 30 days.
What to do: Upgrade Talassoft Industrial Management Software to V.16 or later, which resolves the missing authentication issue. Until upgraded, restrict network access to the Talassoft service (e.g., firewall or VPN) so it is not reachable by unauthenticated users from untrusted networks. Operators should inventory which sites run affected versions from V4 up to but not including V.16 and verify whether the software is exposed to the internet.
| TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software | from V4 before V.16 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.