CVE-2026-19506: RDK-B WebUI race condition vulnerability
Race condition in check.jst in RDK-B WebUI rdkb-2025q4-kirkstone.04.10.26 allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs the ability to send concurrent authentication requests to the RDK-B WebUI. The race condition is exploited by causing those requests to interact with shared authentication state.
Who is exposed to this vulnerability?
Systems running the affected RDK-B WebUI version rdkb-2025q4-kirkstone.04.10.26 are exposed if the WebUI can be reached by a remote attacker. The provided information does not state whether the WebUI is exposed by default.
What access could exploitation provide?
Successful exploitation can allow a remote attacker to gain unauthorized access. The available information does not specify the resulting privilege level or which WebUI functions become available.