CVE-2026-2336 Details
Description
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.
A privilege escalation vulnerability exists in Microchip IStaX versions prior to 2026.03. This vulnerability allows an authenticated low-privileged user to extract a shared per-device cookie secret from their webstax_auth session cookie. The user can then forge a new cookie that grants administrative privileges. The issue arises from the web management interface's cookie design, which inadvertently allows the derivation of reusable secrets that can be exploited to gain higher privileges.
Users are advised to upgrade Microchip IStaX to version 2026.03 or later, which addresses the vulnerability by modifying how authentication cookies are handled, preventing low-privileged users from deriving secrets and creating higher-privilege cookies.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/istax-privilege-escalation-via-weak-cookie-authentication | Microchip Technology | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-331 | Insufficient Entropy | Microchip Technology |
Affected Products
| Product | Versions |
|---|---|
| microchip istax | < 2026.03 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 12, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Microchip Technology |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | New CVE Received | Microchip Technology |