CVE-2026-19397
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the hos
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-306
Not enough EPSS history yet.
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-865439.8 CRI—
———knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.9hCVE-2026-865065.9 MED—
———In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data15hCVE-2026-865028.4 HIG—
———In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts15hCVE-2026-864863.7 LOW—
———In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank15hCVE-2026-864809.8 CRI—
———In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges15hCVE-2026-796458.2 HIG—
———Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.17h