CVE-2026-92626: Control Id Idsecure
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.
Affected products
- Control Id Idsecure: before 4.8.3.0 (fixed in 4.8.3.0)
Published 2026-09-16. Last modified 2026-09-18.