← back
CVE-2026-15706criticalCWE-306

Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 0.4%
from disclosure to weapon0 days
Published on NVDAug 20
1st PoCJul 14
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.