CVE-2026-35095
Session fixation in KTM System e-BOK
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value remains unchanged after successful login. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in the patch published in June 2026.
| CWE | CWE-384 |
| Vendor | ktm system |
| Product | e-bok |
| Published | Jun 30, 2026 |
| Last Updated | Jun 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for ktm system e-bok
Be the first to know when new unknown vulnerabilities affecting ktm system e-bok are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
KTM System / e-BOK
0 < 06.2026
References
Credits
Jacek Korta