CVE-2026-76438: Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability
Published Sep 16, 2026
·Updated
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages.
Affected Software
1 affected component
Cisco BroadWorks CommPilot Application Software
Event History
Sep 16, 2026
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require action from another user?
No. The CVSS vector indicates no user interaction is required.
2
Is the reported impact limited to configuration integrity?
The CVSS vector indicates high integrity impact, with no confidentiality or availability impact.