ZeroHour

CVE-2026-78319

TOCTOU Race Condition in Affected Products Enables Unauthenticated Code Execution

CVSS 4.0
9.3 critical
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-78319 is a Time-of-Check Time-of-Use (TOCTOU) race condition, tracked as CWE-367, in a service running on the affected products, assigned by CERT@VDE. An unauthenticated remote attacker could win a timing race between a security check and the subsequent use of the checked resource, bypassing intended security controls. Successful exploitation may result in the execution of unauthorized code, with high impact on the confidentiality, integrity, and availability of the vulnerable system (CVSS 4.0 base score of 9.3, network vector, no privileges or user interaction required). The available data does not name the affected products or version ranges, so operators should consult the CERT@VDE/vendor advisory to determine whether their deployments are in scope. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS currently estimates only a 0.4% probability of exploitation in the next 30 days (34th percentile).

What to do: Monitor CERT@VDE and the relevant vendor advisories to identify which of your products are affected and which fixed versions are available, since this record does not list products or patch levels. Until you can patch, reduce exposure of the affected service by restricting it to trusted networks and removing any direct internet-facing access. Re-check EPSS/KEV status and exploit releases periodically given the critical 9.3 severity and network-reachable, unauthenticated attack vector.

Affected
Unnamed affected products — see the official CERT@VDE advisory for the product list
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.

Weakness
CWE-367
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.