Executive brief
Control iD iDSecure is an on-premises access control and time attendance management application for Windows. An unauthenticated remote attacker can trigger an unhandled exception in the DGuard integration endpoint by sending crafted requests, causing the iDSecure service to crash and become unavailable. This denial of service requires no authentication and can be triggered repeatedly by an attacker with network access to the service.
Technical details
CVE-2026-92626 is an unauthenticated denial of service affecting the /api/dguardintegration/dguardVersion endpoint in Control iD iDSecure. The vulnerability arises from a null reference exception when the DGuard integration login state is unset or uninitialized. Since the exception is thrown from an asynchronous method that returns void, the exception propagates uncaught and terminates the iDSecure process. No authentication is required to trigger this endpoint, making it remotely exploitable by any network-adjacent attacker. The issue was fixed in version 4.8.3.0 or later, as confirmed by Tenable verification testing.
Affected products
- Control iD iDSecure prior to 4.8.3.0
Timeline
- 2026-09-16: disclosed: Public disclosure via NVD
- 2026-07-20: patched: Control iD released fix in version 4.8.3.0