LOW
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon
Published Feb 13, 2026
2.5
LOWCVSS 4.0
EPSS 0.19%
Description
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.
This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.
Affected products
-
- Version 4.0.0StatusaffectedConstraints-
- Version 4.1.1StatusaffectedConstraints-
- Version 4.1.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Thalesgroup | SafeNet Agent for Windows Logon | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 4.1.3.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-6174 Advisory
- https://supportportal.thalesgroup.com/csm?sys_kb_id=247fd4a42b4a7290061af3f5f291bff1&id=kb_article_view&sysparm_rank=1&sysparm_tsqueryId=5ecb72c73b927610381ecfaf55e45a0b&sysparm_article=KB0030173 vendor-advisory
- https://thalesdocs.com/sta/agents/wla-windows_logon/wla-preinstallation_passwordless/index.html mitigation
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner THA-PSIRT
Published Feb 13, 2026
Updated Sep 3, 2026
Reserved Jan 13, 2026
Link CVE-2026-0872
CISA Vulnrichment
Updated Feb 13, 2026
ENISA EUVD
EUVD-2026-6174 Assigner THA-PSIRT
Published Feb 13, 2026
Updated Sep 3, 2026
Exploited since n/a
Link EUVD-2026-6174