Screen SFT DAB 1.9.3 contains an authentication bypass...
High severity
Unreviewed
Published
Dec 11, 2025
to the GitHub Advisory Database
•
Updated Jan 2, 2026
Description
Published by the National Vulnerability Database
Dec 10, 2025
Published to the GitHub Advisory Database
Dec 11, 2025
Last updated
Jan 2, 2026
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.
References