🔐 CVE Alert

CVE-2026-33591

UNKNOWN 0.0

Authentication bypass on WaptServer

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

CWE CWE-288
Vendor tranquil it systems
Product wapt server
Published Aug 3, 2026
Last Updated Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for tranquil it systems wapt server

Be the first to know when new unknown vulnerabilities affecting tranquil it systems wapt server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Tranquil IT Systems / WAPT Server
2.6.0.16767 ≤ 2.6.1.17787

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wapt.fr: https://www.wapt.fr/en/doc/wapt-changelog.html#wapt-2-6-0-16856-2026-06-09 wapt.fr: https://www.wapt.fr/en/doc/wapt-changelog.html#wapt-2-6-1-17813-2026-06-09 wapt.fr: https://www.wapt.fr/en/doc/wapt-security-bulletin.html

Credits

Brian CHERVY, System Engineer from Antiane, Réunion Team, https://antiane.com CERT-FR