CVE-2026-12183 CRITICAL

CVE-2026-12183: Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials

Vendor Nefteprodukttekhnika Llc
Product BUK TS-G Gas Station Automation System
Weakness CWE-287 · Improper authentication
Published June 13, 2026
Last update August 10, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

What the vulnerability does

01Description

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.

Key dates

02Disclosure timeline

June 13, 2026 CVE published
August 10, 2026 Record updated

Related vulnerabilities

04Related CVE