---
cve: "CVE-2026-76940"
severity: "HIGH"
cvss: 8.7
epss: "30.3%"
vendor: "Ebyte"
kev: false
exploited: false
published: "2026-08-28 00:18:15"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T20:12:42+02:00"
---

# CVE-2026-76940

> 8.7 HIGH · 🧪 PoC

## Beschreibung

The affected Ebyte device does not restrict repeated authentication 
attempts through rate limiting or account lockout mechanisms. This could
 allow an attacker to perform automated authentication attacks against 
deployments that rely on password based authentication.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06>
- <https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-76940) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
