Tata Consultancy Services Cognix Recon Client Authorization Bypass Vulnerability Allowing Privilege Escalation

Vulnerability

An authorization bypass vulnerability has been identified in Tata Consultancy Services (TCS) Cognix Recon Client version 3.0. This vulnerability allows authenticated users to escalate privileges across different roles by sending crafted requests. The issue arises from inadequate enforcement of role-based access control, which enables users to manipulate object identifiers and bypass authorization checks.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling users to gain access to roles and permissions they should not have.

Remediation

TCS has implemented enhanced authorization validation and strengthened role verification mechanisms to prevent the manipulation of user-controlled identifiers. This vulnerability has been validated as remediated in the currently deployed version of the product.

Added: Mar 5, 2026, 7:27 PM
Updated: Mar 5, 2026, 7:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.