๐Ÿ” CVE Alert

CVE-2026-2336

UNKNOWN 0.0

Weak webstax_auth Cookie Authentication Allows Privilege Escalation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.

CWE CWE-331
Vendor microchip
Product istax
Published Apr 16, 2026
Last Updated Apr 16, 2026
Stay Ahead of the Next One

Get instant alerts for microchip istax

Be the first to know when new unknown vulnerabilities affecting microchip istax are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Microchip / IStaX
0 < 2026.03

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
microchip.com: https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/istax-privilege-escalation-via-weak-cookie-authentication

Credits

Rickard Jonsson