CVE-2026-82684 affects Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, exposing a Missing Authorization vulnerability. The flaw could allow unauthenticated or unauthorized attackers to extract sensitive system credentials, configuration data, or flash memory contents from the device. This vulnerability poses a significant risk to operational technology environments where these devices are deployed. CISA has issued an ICS advisory (ICSA-26-246-08) regarding this issue. Firmware updates (version 2.4.2) have been released by Tycon Systems to address the vulnerability. The affected product is an industrial power monitoring device used in OT/ICS environments. Organizations using affected versions are strongly advised to apply the available firmware patches immediately.