CVE-2026-79576
—Authentication Bypass in Digital-Infrastructure 9.6.7 Single Sign-On (SSO)
CVE-2026-79576 is an authentication-bypass flaw (CWE-287) in the Single Sign-On (SSO) component of Digital-Infrastructure, affecting version 9.6.7. A remote attacker can authenticate through the SSO component without supplying a password and be accepted as any user on the system, including the Admin account. With a CVSS 3.1 score of 9.8 (critical) from the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, successful exploitation yields full confidentiality, integrity, and availability impact, effectively granting the attacker complete control of the affected deployment as any chosen user. Any instance running Digital-Infrastructure 9.6.7 with the SSO component is exposed; the CVE record, assigned directly by MITRE, names no vendor, no fixed version, and no vendor advisory. There is no known public proof-of-concept, the issue is not listed in CISA KEV, and EPSS is low (0.3%, 26th percentile), so no exploitation is currently known.
What to do: Upgrade to a patched release as soon as one is published; the current record does not specify a fixed version, so monitor the vendor or CNA for an update. As interim mitigation, restrict network access to the SSO endpoint (firewall/VPN, or disable SSO if feasible) and review authentication logs for logins to Admin or other accounts that lack corresponding password events. Confirm the deployed Digital-Infrastructure version and whether the SSO component is in use.
| Digital-Infrastructure (SSO component) | 9.6.7 (only version cited; whether earlier versions are also affected is not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.