{"id":"CVE-2026-92625","published":"2026-09-16T16:17:23.760","lastModified":"2026-09-18T19:18:42.907","description":"Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.\n\n\nThe /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous restart cycle, rendering it unavailable.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://www.tenable.com/security/research/tra-2026-56","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}