CVE-2020-36923: Sony Bravia Signage
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.
Affected products
- Sony Bravia Signage: up to and including 1.7.8
Published 2026-01-06. Last modified 2026-06-17.