ZeroHour

CVE-2026-79576

Authentication Bypass in Digital-Infrastructure 9.6.7 Single Sign-On (SSO)

CVSS 3.1
9.8 critical
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-79576 is an authentication-bypass flaw (CWE-287) in the Single Sign-On (SSO) component of Digital-Infrastructure, affecting version 9.6.7. A remote attacker can authenticate through the SSO component without supplying a password and be accepted as any user on the system, including the Admin account. With a CVSS 3.1 score of 9.8 (critical) from the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, successful exploitation yields full confidentiality, integrity, and availability impact, effectively granting the attacker complete control of the affected deployment as any chosen user. Any instance running Digital-Infrastructure 9.6.7 with the SSO component is exposed; the CVE record, assigned directly by MITRE, names no vendor, no fixed version, and no vendor advisory. There is no known public proof-of-concept, the issue is not listed in CISA KEV, and EPSS is low (0.3%, 26th percentile), so no exploitation is currently known.

What to do: Upgrade to a patched release as soon as one is published; the current record does not specify a fixed version, so monitor the vendor or CNA for an update. As interim mitigation, restrict network access to the SSO endpoint (firewall/VPN, or disable SSO if feasible) and review authentication logs for logins to Admin or other accounts that lack corresponding password events. Confirm the deployed Digital-Infrastructure version and whether the SSO component is in use.

Affected
Digital-Infrastructure (SSO component)9.6.7 (only version cited; whether earlier versions are also affected is not specified)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.

Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.