CVE-2026-64827 (matched: php)

  • Monday, 3rd August, 2026
  • 16:04pm

A security flaw has been identified in older versions of Telenia Software TVox: all 26.x releases up to version 26.5.3, and all 24.x releases up to version 24.9.21. This flaw creates an authentication bypass, meaning unauthorized users can access protected sections of the service without entering valid login credentials.

The issue exists in a file called set_env.php. If an attacker adds "/login_admin.php" to the end of the web address for any PHP script in the TVox manager area, the system incorrectly treats them as an approved user and skips the standard login check. This grants unauthenticated users full access to every management script in that section of the service.

If you run one of these affected TVox versions on your hosting account, this could let bad actors access your service's management tools without permission. They may be able to adjust settings, view sensitive information, or make unauthorized changes to your TVox setup.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-64827

« Back