VDB
CVE-2026-19506
CVE-2026-19506
PUBLISHED
Reported by certcc · Published August 19, 2026
Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| RDK | RDK-B WebUI | rdkb-2025q4-kirkstone |
| RDK | RDK-B WebUI | rdkb-2025q4-kirkstone |
Timeline
- Aug 19, 2026 CVE Published
- Aug 22, 2026 Coalition ESS Score