CVE-2026-16876: UNIVERGE UNIVERGE IX-R/IX-V vulnerability
Published Sep 7, 2026
·Updated
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
Affected Software
1 affected component
UNIVERGE UNIVERGE IX-R/IX-V
Event History
Sep 7, 2026
CVE Published
via MITRE·12:48 AM
Data Sourced
via MITRE·12:48 AM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are exposed to remote exploitation?
UNIVERGE IX-R/IX-V devices with their WebGUI reachable via the internet are exposed to the described attack path.
2
Does an attacker need valid WebGUI credentials?
No. The vulnerability allows authentication to be bypassed by tampering with WebGUI messages sent to the device.
3
What access could an attacker gain after successful exploitation?
An attacker could execute arbitrary CLI commands on the affected device.