CVE-2026-35095 Details
Description
KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value remains unchanged after successful login. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in the patch published in June 2026.
A session fixation vulnerability has been identified in KTM System e-BOK, allowing attackers to hijack authenticated user sessions. This issue arises because the application permits clients to set session identifiers before authentication. Once a cookie with a valid name is established, its value remains unchanged after a successful login. Consequently, an attacker can fix a session ID for a victim and later take over the authenticated session. This vulnerability affects all versions of KTM System e-BOK prior to June 2026.
Users are advised to update to the version of KTM System e-BOK released in June 2026 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/06/CVE-2026-35095/ | [email protected] | AdvisoryBundleRemedy |
| https://ktmsystem.pl/internetowe-biuro-obslugi-klienta/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-384 | Session Fixation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| KTM System e-BOK | < 06.2026 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion