CVE-2026-78319
—TOCTOU Race Condition in Affected Products Enables Unauthenticated Code Execution
CVE-2026-78319 is a Time-of-Check Time-of-Use (TOCTOU) race condition, tracked as CWE-367, in a service running on the affected products, assigned by CERT@VDE. An unauthenticated remote attacker could win a timing race between a security check and the subsequent use of the checked resource, bypassing intended security controls. Successful exploitation may result in the execution of unauthorized code, with high impact on the confidentiality, integrity, and availability of the vulnerable system (CVSS 4.0 base score of 9.3, network vector, no privileges or user interaction required). The available data does not name the affected products or version ranges, so operators should consult the CERT@VDE/vendor advisory to determine whether their deployments are in scope. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS currently estimates only a 0.4% probability of exploitation in the next 30 days (34th percentile).
What to do: Monitor CERT@VDE and the relevant vendor advisories to identify which of your products are affected and which fixed versions are available, since this record does not list products or patch levels. Until you can patch, reduce exposure of the affected service by restricting it to trusted networks and removing any direct internet-facing access. Re-check EPSS/KEV status and exploit releases periodically given the critical 9.3 severity and network-reachable, unauthenticated attack vector.
| Unnamed affected products — see the official CERT@VDE advisory for the product list | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.
- Weakness
- CWE-367
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.