Executive brief
Tyler Identity Local (TID-L), an identity management solution, contains documented default administrative credentials that are not required to be changed during deployment. An attacker can use these well-known credentials to gain full administrative access to the system over the network. This could lead to unauthorized access to sensitive identity data, service disruption, or complete system takeover. Note that this product has been unsupported since 2021 and is no longer distributed.
Technical details
Tyler Identity Local (TID-L) is vulnerable to the use of default credentials (CWE-1392). The software ships with administrative accounts using publicly documented passwords, and the installation process does not enforce a credential change. A remote, unauthenticated attacker can exploit this by logging into the administrative interface using these default values. Successful exploitation grants full control over the identity management platform. The product reached end-of-life in 2021 and no official patches are expected; users are advised to migrate to supported alternatives or manually ensure all default accounts are disabled or updated with strong passwords.
Affected products
- Tyler Technologies Identity Local (TID-L) All versions
Timeline
- 2020-12: other: Product distribution ceased
- 2021: other: Product support ended
- 2026-05-19: advisory: CVE published and disclosed