---
id: CVE-2026-92378
title: >-
  A session management

  vulnerability exists in the Legacy UI Reduced Function Login feature of
  NT-ware

  uniFLOW Online
summary: >-
  A session management

  vulnerability exists in the Legacy UI Reduced Function Login feature of
  NT-ware

  uniFLOW Online. Under specific timing conditions during Service Offline

  Emergency Mode, a previously authenticated session may be retain…
severity: medium
cvss: 4.1
cvssVector: 'CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-613
vendor: NT-ware
product: uniFLOW Online
affected:
  - uniflow_online <= 2026.2
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:58:00.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92378'
references:
  - url: >-
      https://ntware.atlassian.net/wiki/spaces/SA/pages/14160592897/Security+Advisory+Previous+login+session+retained+when+entering+Reduced+Function+Login
    label: 4586e0a2-224d-4f8a-9cb4-8882b208c0b3
  - url: 'https://www.canon-europe.com/psirt/advisory-information/'
    label: 4586e0a2-224d-4f8a-9cb4-8882b208c0b3
tags:
  - nvd
  - cve.org
epss: 0.00123
epssPercentile: 0.01791
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T14:48:32.843106Z'
cvssSource: cna
ingestedAt: '2026-09-23T08:20:37.597Z'
---

## Overview

A session management
vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware
uniFLOW Online. Under specific timing conditions during Service Offline
Emergency Mode, a previously authenticated session may be retained after
logout, which could allow a subsequent user to be authenticated as the previous
user and gain unauthorised limited access to device functionality.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
