CVE-2026-64827
Telenia TVox 26.5.3 Authentication Bypass via set_env.php
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
| CWE | CWE-807 |
| Vendor | telenia software |
| Product | tvox |
| Published | Aug 3, 2026 |
| Last Updated | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for telenia software tvox
Be the first to know when new critical vulnerabilities affecting telenia software tvox are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Telenia Software / TVox
26.0.0 โค 26.5.3 24.0.0 โค 24.9.21
References
Credits
Egidio Romano