{"id":"CVE-2026-92378","title":"A session management\nvulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware\nuniFLOW Online","summary":"A session management\nvulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware\nuniFLOW Online. Under specific timing conditions during Service Offline\nEmergency Mode, a previously authenticated session may be retain…","severity":"medium","cvss":4.1,"cvssVector":"CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-613"],"vendor":"NT-ware","product":"uniFLOW Online","affected":["uniflow_online <= 2026.2"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:58:00.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92378","references":[{"url":"https://ntware.atlassian.net/wiki/spaces/SA/pages/14160592897/Security+Advisory+Previous+login+session+retained+when+entering+Reduced+Function+Login","label":"4586e0a2-224d-4f8a-9cb4-8882b208c0b3"},{"url":"https://www.canon-europe.com/psirt/advisory-information/","label":"4586e0a2-224d-4f8a-9cb4-8882b208c0b3"}],"tags":["nvd","cve.org"],"epss":0.00177,"epssPercentile":0.07453,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-23T14:48:32.843106Z"},"cvssSource":"cna","ingestedAt":"2026-09-23T08:20:37.597Z","slug":"CVE-2026-92378","body":"## Overview\n\nA session management\nvulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware\nuniFLOW Online. Under specific timing conditions during Service Offline\nEmergency Mode, a previously authenticated session may be retained after\nlogout, which could allow a subsequent user to be authenticated as the previous\nuser and gain unauthorised limited access to device functionality.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":22.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}