What is CVE-2026-55729?
This critical vulnerability is an exposure of sensitive information (CWE-200) in Loytec LWEB-802 versions prior to 5.0.8. It allows an unauthenticated remote attacker to leak management credentials stored in the browser's `localStorage` via a crafted link. All platforms are affected, and immediate update to version 5.0.8 is recommended.
Azərbaycanca: Bu kritik boşluq Loytec LWEB-802 sistemlərində (5.0.8-dən əvvəlki versiyalar) yerləşən həssas məlumat ifşasıdır (CWE-200). Zəiflik brauzerin `localStorage`-də saxlanılan idarəetmə etimadnamələrinin xüsusi hazırlanmış keçid vasitəsilə autentifikasiya olunmamış uzaqdan hücumçu tərəfindən oğurlanmasına imkan verir. Bütün platformalar təsirlənir və dərhal 5.0.8 versiyasına yenilənmə tövsiyə edilir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which Loytec product is affected by CVE-2026-55729?
CVE-2026-55729 affects Loytec LWEB-802 systems running versions prior to 5.0.8.
What information can an attacker steal via CVE-2026-55729?
An attacker can leak management credentials stored in the browser's `localStorage` via a crafted link.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.