HIGH
Aircoookie
CVE published 2026-08-05
CVE-2026-71264
Unauthenticated configuration disclosure and full configuration-write access in WLED's web server allows attackers to gain unauthorized access to device settings. This vulnerability affects WLED devices, potentially allowing attackers to tamper with configurations or gain unauthorized access. Evidence limits prevent detailed analysis of specific attack vectors or exploitability. The vulnerability is track [truncated]