CVE-2026-35098
Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform unlimited authentication requests. This lack of rate‑limiting enables efficient brute‑force attacks against user accounts. When combined with vulnerability CVE-2026-35097, where passwords are restricted to a six‑digit numeric format, this becomes a critical issue, as such passwords can be brute‑forced in a relatively short time. This issue was fixed in the patch published in June 2026.
| CWE | CWE-307 |
| Vendor | ktm system |
| Product | e-bok |
| Published | Jun 30, 2026 |
| Last Updated | Jun 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for ktm system e-bok
Be the first to know when new unknown vulnerabilities affecting ktm system e-bok are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
KTM System / e-BOK
0 < 06.2026
References
Credits
Jacek Korta