CVE-2026-1363: Jnc i6

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain administrator privileges by manipulating the web front-end.

Affected products

  • Jnc i6: version 0 only
  • Jnc Iaqs: version 0 only

Published 2026-01-23. Last modified 2026-06-17.