CVE-2026-73778
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote
CVSS
8.1
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 1, 2026 · Last modified: Sep 1, 2026
Not enough EPSS history yet.
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.
No related CVEs by CWE or product.