🔐 CVE Alert

CVE-2026-35096

UNKNOWN 0.0

Cross-Site Request Forgery (CSRF) in KTM System e-BOK

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged POST request to the application. This allows the attacker to trigger an unauthorized email or password change on behalf of the victim without their knowledge or interaction. This issue was fixed in the patch published in June 2026.

CWE CWE-352
Vendor ktm system
Product e-bok
Published Jun 30, 2026
Last Updated Jun 30, 2026
Stay Ahead of the Next One

Get instant alerts for ktm system e-bok

Be the first to know when new unknown vulnerabilities affecting ktm system e-bok are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

KTM System / e-BOK
0 < 06.2026

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/06/CVE-2026-35095/ ktmsystem.pl: https://ktmsystem.pl/internetowe-biuro-obslugi-klienta/

Credits

Jacek Korta