CVE-2026-26341 Details
Description
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.
A vulnerability exists in Tattile Smart+, Vega, and Basic device families with firmware versions through 1.181.5. These devices are shipped with default credentials that are not required to be changed during installation or commissioning. An attacker with access to the management interface can use the default credentials to gain administrative access, allowing unauthorized modification of device configurations and access to sensitive data.
Tattile has acknowledged this vulnerability and plans to release a patch in May 2026. Users should contact Tattile for guidance on updating to the latest firmware version once it is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tattile.com/ | [email protected] | Product |
| https://www.vulncheck.com/advisories/tattile-smart-vega-basic-default-credentials | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5977.php | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1392 | Use of Default Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tattile smart+ firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile smart+ | All versions |
CPE
Remediation
| |
| tattile tolling+ firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile tolling+ | All versions |
CPE
Remediation
| |
| tattile smart+ speed firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile smart+ speed | All versions |
CPE
Remediation
| |
| tattile smart+ traffic light firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile smart+ traffic light | All versions |
CPE
Remediation
| |
| tattile axle counter firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile axle counter | All versions |
CPE
Remediation
| |
| tattile vega53 firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile vega53 | All versions |
CPE
Remediation
| |
| tattile vega33 firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile vega33 | All versions |
CPE
Remediation
| |
| tattile vega11 firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile vega11 | All versions |
CPE
Remediation
| |
| tattile basic mk2 firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile basic mk2 | All versions |
CPE
Remediation
| |
| tattile anpr mobile firmware | <= 1.181.5 |
CPE
Remediation
| |
| tattile anpr mobile | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 24, 2026 | New CVE Received | [email protected] |