Junglewise Threat Intelligence

CVE-2026-92625: Control iD iDSecure unauthenticated denial of service in service restart endpoint

CVE-2026-92625 · Severity: high · CVSS 7.5 · Published 2026-09-16

Executive brief

Control iD iDSecure is an on-premises access control and time attendance management system. An unauthenticated attacker can repeatedly trigger service restarts through a publicly accessible API endpoint, continuously cycling the service and making it unavailable to users. This disrupts access control operations and could prevent authorized personnel from entering secured areas or recording time attendance.

Technical details

The /api/license/restartService endpoint in iDSecure is accessible without authentication. The endpoint invokes a routine that terminates the iDSecure service process and relaunches it via a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly over the network to hold the service in a continuous restart cycle, rendering it unavailable. The vulnerability affects versions prior to 4.8.3.0. A fix has been released in version 4.8.3.0 or later.

Affected products

  • Control iD iDSecure prior to 4.8.3.0

Timeline

  • 2026-09-16: disclosed: Public disclosure via NVD and Tenable advisory
  • 2026-07-20: patched: Fix released in version 4.8.3.0
  • 2026-08-03: other: Tenable verified fix in version 4.8.2.0

References

Related threats