


Perceptive Security
SOC/SIEM Consultancy

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where t…
Published:
3 August 2026 at 00:00:00
Alert date:
3 August 2026 at 17:06:10
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Identity & Access
Telenia Software TVox versions 26.5.3 and prior (26.x) and 24.9.21 and prior (24.x) contain an authentication bypass vulnerability in set_env.php. The vulnerable function redirectToLoginAdminIRequestHaveAccessToken() derives the current page name from the PHP_SELF variable and skips authentication if the value matches 'login_admin.php'. Attackers can exploit this by appending '/login_admin.php' to any target PHP script path, causing the authentication check to be bypassed. This allows unauthenticated access to all PHP scripts located under the manager HTML directory. The vulnerability requires no authentication or special privileges to exploit, making it highly critical. Organizations using affected versions of Telenia TVox should apply patches or mitigations immediately.
Technical details
Mitigation steps:
Affected products:
Telenia Software TVox 26.5.3
Telenia Software TVox 24.9.21
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-64827
https://karmainsecurity.com/KIS-2026-14
https://www.teleniasoftware.com/
https://www.vulncheck.com/advisories/telenia-tvox-authentication-bypass-via-set-env-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
