# Slican PBX systems vulnerable to authentication bypass

Published: 2026-05-27 · Severity: high · Sectors: telecommunications
Canonical: https://vorant.io/reports/f7cf538b-eb06-59a1-b1a0-279ec13b03bb/slican-pbx-systems-vulnerable-to-authentication-bypass

> Three critical vulnerabilities in Slican telephone exchanges allow unauthenticated attackers to bypass authentication and gain full administrative access.

CERT Polska has disclosed three critical vulnerabilities affecting Slican telephone exchange systems that allow complete authentication bypass and unauthorized administrative access. CVE-2026-35087 enables attackers to bypass login credentials through command execution, while CVE-2026-35089 allows deduction of secure keys due to predictable generation based on obtainable device properties. Most significantly, CVE-2026-35090 permits remote control panel access via telephone connection with a specific caller ID, bypassing all authentication regardless of configuration settings.

Patches are available for current products including NCP (1.24.0250), IPx series (6.61.0040), CCT-1668 (6.56.0430), MAC-6400 (6.56.0430), and CXS-0424 (6.30.0510). However, end-of-life products using version 4.xx and below—discontinued in 2011-2012—remain vulnerable and require hardware upgrades to receive patches. The vendor recommends affected users contact their service department for upgrade options.

The vulnerabilities were responsibly disclosed by Grupa ŻN through CERT Polska's coordinated vulnerability disclosure process. Organizations using Slican telephone exchanges should prioritize patching to prevent unauthorized access to telecommunications infrastructure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35087, CVE-2026-35089, CVE-2026-35090

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-35087

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f7cf538b-eb06-59a1-b1a0-279ec13b03bb/slican-pbx-systems-vulnerable-to-authentication-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
