Telenia Software TVox Authentication Bypass Vulnerability Under Investigation
Telenia Software TVox versions 26.5.3 and prior 26.x, and 24.9.21 and prior 24.x, reportedly contain an authentication bypass vulnerability that could allow unauthenticated access to scripts under the manager HTML directory.
What happened
An early warning has been issued regarding a potential critical vulnerability in Telenia Software TVox. Versions 26.5.3 and prior in the 26.x series, and 24.9.21 and prior in the 24.x series, appear to have an authentication bypass issue in the set_env.php script. This vulnerability, tracked as CVE-2026-64827, allows attackers to bypass authentication by appending '/login_admin.php' to any PHP script's path, potentially gaining unauthorized access to scripts under the manager HTML directory. The severity of this vulnerability is rated as CRITICAL with a CVSS score of 9.8. It is under investigation and users are advised to upgrade to versions beyond 26.5.3 for the 26.x series and beyond 24.9.21 for the 24.x series to mitigate potential risks. For more detailed information, consult the primary sources.
How 0Day mitigates this
tvox is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.