{
  "title": "CVE of the day — CVE-2026-78167 (CVSS 10,0, critical)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE of the day — CVE-2026-78167 (CVSS 10,0, critical)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-78167: critical vulnerability, CVSS 10,0/10, improper authentication type, exploitable"
    }
  ],
  "description": "CVE-2026-78167: critical vulnerability, CVSS 10,0/10, improper authentication type, exploitable remotely, without privileges, without user interaction. A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon check session url of the component Session..",
  "keywords": [
    "c",
    "cve-2026-78167",
    "vulnerability",
    "critical vulnerability",
    "♪",
    "cvs",
    "cybersecurity",
    "cybersecurity",
    "♪",
    "security update"
  ],
  "scenes": [
    {
      "title": "CVE-2026- 781",
      "subtitle": "CVSS 10.0",
      "text": "CVE-2026-78167: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database."
    },
    {
      "title": "Improper Authentication",
      "subtitle": "improper authentication · CVSS v3.1",
      "text": "A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon check session url of the component session Validation Handler. This manipulation causes abuse authentication.."
    },
    {
      "title": "EXPOSURE AND MITIGATION",
      "subtitle": "remotely exploitable, without privileges, without user interaction",
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ],
  "publication_date": "2026-08-25T01:00:31.268Z",
  "duration": 20,
  "topic": "cve",
  "lang": "en",
  "translation_group": "cve-2026-08-25",
  "poster": "cve-2026-08-25-en.jpg",
  "preview": "cve-2026-08-25-en.gif",
  "og_card": "cve-2026-08-25-en.og.jpg",
  "audiogram": "cve-2026-08-25-en.audiogram.mp4",
  "captions": "cve-2026-08-25-en.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-78167: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database. A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon check session url of the component session Validation Handler. This manipulation causes abuse authentication.. Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-78167: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon check session url of the component session Validation Handler. This manipulation causes abuse authentication.."
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ]
}