What is CVE-2026-64827?
An authentication bypass vulnerability exists in set_env.php in Telenia Software TVox versions 26.5.3 and prior 26.x, and 24.9.21 and prior 24.x. The redirectToLoginAdminIRequestHaveAccessToken() function derives the page name from PHP_SELF and skips authentication when the value is manipulated. Users should immediately upgrade to a patched version.
Azərbaycanca: Telenia Software TVox-un 26.5.3 və əvvəlki 26.x, həmçinin 24.9.21 və əvvəlki 24.x versiyalarında set_env.php faylında autentifikasiyadan yan keçmə zəifliyi aşkarlanıb. Bu boşluq redirectToLoginAdminIRequestHaveAccessToken() funksiyasının PHP_SELF dəyərindən səhifə adını təyin edərək autentifikasiyanı atlamasına səbəb olur. İstifadəçilər dərhal yenilənmiş versiyalara keçid etməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of Telenia Software TVox are affected by the CVE-2026-64827 authentication bypass vulnerability?
The vulnerability affects TVox versions 26.5.3 and prior 26.x, and 24.9.21 and prior 24.x.
How does the CVE-2026-64827 vulnerability bypass authentication in set_env.php?
The vulnerability occurs because the redirectToLoginAdminIRequestHaveAccessToken() function derives the page name from PHP_SELF and skips authentication when this value is manipulated.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.