Improper Authentication in TreeFrog Framework by TreeFrogFramework
CVE-2026-19974

6.3MEDIUM

Key Information:

Vendor
CVE Published:
17 August 2026

What is CVE-2026-19974?

A security flaw has been identified in the TreeFrog Framework affecting the Session Cookie Handler component. This vulnerability arises from an issue in the std::strncmp function located in the src/tsessioncookiestore.cpp file, which may lead to improper authentication. Attackers can exploit this vulnerability remotely, although the complexity of such attacks is considered high, and they are not straightforward to execute. The exploit for this vulnerability has been publicly disclosed, raising concerns for users of the affected versions of the TreeFrog Framework.

Affected Version(s)

treefrog-framework 2.11.0

treefrog-framework 2.11.1

treefrog-framework 2.11.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theodosis (VulDB User)
VulDB CNA Team
.