Junglewise Threat Intelligence

CVE-2026-15706: Baylan Smart Meter Management Application authentication bypass

CVE-2026-15706 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Executive brief

Baylan Smart Meter Management Application (BMS) is software that manages and monitors smart meter devices for utility providers. A missing authentication vulnerability allows attackers to bypass security controls and access critical functions without valid credentials, potentially enabling unauthorized meter data manipulation, service disruption, or fraudulent meter readings.

Technical details

This vulnerability is a missing authentication issue in the Baylan Smart Meter Management Application that permits unauthenticated access to critical functions. The affected component fails to properly validate user identity before processing sensitive operations. An attacker with network access to the application can exploit this to bypass authentication mechanisms and invoke protected functionality without credentials. The vulnerability affects BMS versions before v1.1.10.142. A patch is available in version 1.1.10.142 or later.

Affected products

  • Baylan Measuring Instruments Industry and Trade Inc. Smart Meter Management Application before v1.1.10.142

Timeline

  • 2026-08-20: disclosed: CVE-2026-15706 published on NVD

References