CVE-2026-22096: Evbee DC-80

Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.

Affected products

  • Evbee DC-80: before 1.5.1 (fixed in 1.5.1)

Published 2026-07-13. Last modified 2026-07-13.