Executive brief
Control iD iDSecure is an on-premises access control and time attendance management system. An unauthenticated attacker can repeatedly trigger service restarts through a publicly accessible API endpoint, continuously cycling the service and making it unavailable to users. This disrupts access control operations and could prevent authorized personnel from entering secured areas or recording time attendance.
Technical details
The /api/license/restartService endpoint in iDSecure is accessible without authentication. The endpoint invokes a routine that terminates the iDSecure service process and relaunches it via a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly over the network to hold the service in a continuous restart cycle, rendering it unavailable. The vulnerability affects versions prior to 4.8.3.0. A fix has been released in version 4.8.3.0 or later.
Affected products
- Control iD iDSecure prior to 4.8.3.0
Timeline
- 2026-09-16: disclosed: Public disclosure via NVD and Tenable advisory
- 2026-07-20: patched: Fix released in version 4.8.3.0
- 2026-08-03: other: Tenable verified fix in version 4.8.2.0