CVE-2026-4767
published 2026-07-02CVE-2026-4767: Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.61%
46.9th percentile
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse.
This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tr7_cyber_defense_inc | waf-asp | >= v1.0.324.900 < v1.4.0.117 | v1.4.0.117 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc.
ghsa_unreviewed·2026-07-02
CVE-2026-4767 [CRITICAL] CWE-306 Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc.
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse.
This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
VulDB
TR7 Cyber Defense WAF-ASP prior 1.4.0.117 missing authentication
vuldb·2026-07-02·CVSS 9.8
CVE-2026-4767 [CRITICAL] TR7 Cyber Defense WAF-ASP prior 1.4.0.117 missing authentication
A vulnerability was found in TR7 Cyber Defense WAF-ASP. It has been classified as critical. This affects an unknown function. Performing a manipulation results in missing authentication.
This vulnerability was named CVE-2026-4767. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-02
Published