CVE-2026-19506: Rdk Rdk-B Webui

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state.

Affected products

  • Rdk Rdk-B Webui

Published 2026-08-19. Last modified 2026-09-03.