CVE-2026-15706: Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS
Published Aug 20, 2026
·Updated
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass.
This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.
Affected Software
1 affected component
Baylan Smart Meter Management Application (BMS)<1.1.10.142
Event History
Aug 20, 2026
CVE Published
via MITRE·01:27 PM
Data Sourced
via MITRE·01:27 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Baylan Smart Meter Management Application (BMS) versions before 1.1.10.142 are affected.
2
What does an attacker need to exploit this issue?
The vulnerability is rated network-accessible with low attack complexity and requires no privileges or user interaction. It allows authentication bypass in the Management API.
3
What is the potential impact of successful exploitation?
Successful exploitation can affect confidentiality, integrity, and availability at high impact levels. The reported CVSS severity is critical, with a score of 9.8.