Back to overview

CVE-2026-50176

HIGH
7.5
CVSS 3.1
Description
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

Metadata

CVE ID
CVE-2026-50176
State
PUBLISHED
Assigner
icscert
Reserved
2026-06-18 19:23 UTC
Published
2026-06-25 20:58 UTC
Last updated
2026-06-25 20:58 UTC
Primary CWE
CWE-307
CWE-307
Vendor / Product
EVoke / EVoke CSMS
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products (1)
VendorProductPlatformVersions
EVoke EVoke CSMS All versions
Weakness (CWE)
CWESourceDescription
CWE-307 cna CWE-307
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview