CRITICAL 9.8 CVE-2026-80349 Published 26 Aug 2026

TarsWeb SSO Bypass Vulnerability

Worried this affects one of your servers?

TarsWeb, a web application framework, is vulnerable to unauthorized access due to improper handling of the X-Forwarded-For header and lack of authentication checks.

TarsWeb versions prior to 3.0.16 are affected. An attacker can exploit this vulnerability to gain unauthorized access to user and role administration, service configuration, and package upload and deployment features.

Reference: CVE-2026-80349 on NVD

← Back to Security News