Junglewise Threat Intelligence

CVE-2026-64940: Nishishi Tegalog permissive regular expression auth bypass

CVE-2026-64940 · Severity: high · CVSS 8.6 · Published 2026-08-10

Executive brief

Tegalog is a personal memo logger CGI application used to maintain online journals and logs. A flaw in the application's login validation logic allows an attacker to bypass authentication and gain administrative access to the management console, enabling them to modify or delete all logged content and settings without authorization.

Technical details

The vulnerability is a permissive regular expression flaw (CWE-625) in Tegalog's authentication mechanism. An attacker with network access to the affected CGI application can exploit this validation bypass to log in to the management console without valid credentials. Once authenticated, they can perform any administrative operation available through the console. The vulnerability affects all versions prior to 4.9.0 (released 2026-06-29). The fix is available by upgrading to version 4.9.0 or later.

Affected products

  • Nishishi Factory Tegalog -Fumy Otegaru Memo Logger- 4.8.4 and earlier (all versions prior to 4.9.0)

Timeline

  • 2026-07-29: disclosed
  • 2026-06-29: patched: Version 4.9.0 released with fix
  • 2026-08-10: advisory

References