Junglewise Threat Intelligence

CVE-2026-18771: TMT Talassoft Industrial Management Software authentication bypass

CVE-2026-18771 · Severity: high · CVSS 7.5 · Published 2026-09-01

Technologies: TMT Machine Industry and Trade Ltd. Co Talassoft Industrial Management Software. Vendors: TMT Machine Industry and Trade Ltd. Co.

Executive brief

Talassoft Industrial Management Software, used to control and manage manufacturing operations, contains a missing authentication vulnerability in a critical function. An attacker can bypass authentication controls and gain unauthorized access to core management features without valid credentials, potentially allowing control over industrial equipment and processes.

Technical details

The vulnerability is a missing authentication issue affecting a critical function in Talassoft Industrial Management Software versions V4 through before V.16. The flaw allows authentication bypass, enabling unauthenticated attackers to access protected functionality. The vulnerability is network-reachable and does not require prior authentication or user interaction. Successful exploitation could grant an attacker unauthorized access to industrial control and management capabilities. Patches are available in version V.16 and later.

Affected products

  • TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software V4 before V.16

Timeline

  • 2026-09-01: disclosed

References

Related threats