Tata Consultancy Services Cognix Recon Client Missing Authentication and Authorization Vulnerability

Vulnerability

A vulnerability exists in the web API of Tata Consultancy Services (TCS) Cognix Recon Client version 3.0, due to missing authentication and authorization. This flaw allows remote attackers to access application functionality without proper restrictions. The affected endpoints include reconciliations, Scheduler, and DynamicReport.

Impact

Exploitation of this vulnerability could lead to unauthorized access to application functionality, bypassing authentication and authorization controls.

Remediation

TCS has implemented mandatory authentication requirements and improved authorization validation across the affected API endpoints. This vulnerability has been verified as remediated in the current version of the product.

Added: Mar 5, 2026, 7:25 PM
Updated: Mar 5, 2026, 7:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.