Junglewise Threat Intelligence

CVE-2026-76438: Cisco BroadWorks CommPilot authorization bypass in web management interface

CVE-2026-76438 · Severity: medium · CVSS 6.5 · Published 2026-09-16

Executive brief

Cisco BroadWorks CommPilot is a web-based management and communication application used by enterprises. A missing authorization check in the management interface allows authenticated users with low privileges to modify system configurations they should not have access to, potentially disrupting service or gaining unauthorized control over communication settings.

Technical details

This vulnerability is a missing authorization check (CWE-863) in the web-based management interface of Cisco BroadWorks CommPilot Application Software. An authenticated attacker with low privileges can craft and send HTTP requests to bypass authorization checks and alter configurations on select administrative pages. The vulnerability requires authentication to exploit, but grants unauthorized modification capability to an already-authenticated user. Cisco has released software fixes for affected versions (24.0.2026.07, 27.0.2026.08, and patches for earlier versions) and notes there are no workarounds available.

Affected products

  • Cisco BroadWorks CommPilot Application Software 23.0, 24.0 (before 24.0.2026.07), 25.0, 26.0, 27.0 (before 27.0.2026.08)
  • Cisco BroadWorks Application Server 24.0 (before patch AP.as.24.0.944.ap385770), 25.0–26.x, 27.0 (before 27.0.2026.08)

Timeline

  • 2026-09-16: disclosed: Advisory published by Cisco PSIRT
  • 2026-09-16: patched: Fixed releases available: CommPilot 24.0.2026.07, 27.0.2026.08; Application Server patch AP.as.24.0.944.ap385770

References

Related threats