Home

Description

Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.

PUBLISHED Reserved 2026-02-20 | Published 2026-02-28 | Updated 2026-02-28 | Assigner Microchip




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-306 Missing Authentication for Critical Function

Product status

Default status
unaffected

11.0 (custom)
affected

Timeline

2026-02-04:Reported

Credits

Steve Lin reporter

Bastion Security reporter

References

www.microchip.com/...tra-authentication-bypass-vulnerability vendor-advisory

cve.org (CVE-2026-2844)

nvd.nist.gov (CVE-2026-2844)

Download JSON