{
  "title": "CVE of the day — CVE-2026-16299 (CVSS 9,8, critical)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE of the day — CVE-2026-16299 (CVSS 9,8, critical)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-16299: critical vulnerability, CVSS 9,8/10, improper authentication type, exploitable"
    }
  ],
  "description": "CVE-2026-16299: critical vulnerability, CVSS 9,8/10, improper authentication type, exploitable remotely, without privileges, without user interaction. The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to..",
  "keywords": [
    "c",
    "cve-2026-16299",
    "vulnerability",
    "critical vulnerability",
    "♪",
    "cvs",
    "cybersecurity",
    "cybersecurity",
    "♪",
    "security update"
  ],
  "scenes": [
    {
      "title": "CVE-2026- 16299",
      "subtitle": "CVSS 9,8",
      "text": "CVE-2026-16299: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database."
    },
    {
      "title": "Improper Authentication",
      "subtitle": "improper authentication · CVSS v3.1",
      "text": "The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which.."
    },
    {
      "title": "EXPOSURE AND MITIGATION",
      "subtitle": "remotely exploitable, without privileges, without user interaction",
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ],
  "publication_date": "2026-08-12T01:10:01.431Z",
  "duration": 20,
  "topic": "cve",
  "lang": "en",
  "translation_group": "cve-2026-08-12",
  "poster": "cve-2026-08-12-en.jpg",
  "preview": "cve-2026-08-12-en.gif",
  "og_card": "cve-2026-08-12-en.og.jpg",
  "audiogram": "cve-2026-08-12-en.audiogram.mp4",
  "captions": "cve-2026-08-12-en.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-16299: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database. The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which.. Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-16299: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which.."
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ]
}