---
id: CVE-2026-92625
title: "Control iD iDSecure versions prior to\_4.8.3.0 are affected by an unauthenticated\_Denial of Service.\n\n\nThe /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecu…"
summary: "Control iD iDSecure versions prior to\_4.8.3.0 are affected by an unauthenticated\_Denial of Service.\n\n\nThe /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecu…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-306
vendor: Control iD
product: iDSecure
affected:
  - iDSecure < 4.8.3.0
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:18:42.907'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92625'
references:
  - url: 'https://www.tenable.com/security/research/tra-2026-56'
    label: vulnreport@tenable.com
tags:
  - nvd
  - cve.org
epss: 0.00658
epssPercentile: 0.49342
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T17:35:36.369128Z'
ingestedAt: '2026-09-16T15:58:38.774Z'
---

## Overview

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.


The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous restart cycle, rendering it unavailable.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
