Privilege Escalation Vulnerability in Microchip IStaX Web Application
CVE-2026-2336
8.7HIGH
What is CVE-2026-2336?
A vulnerability in the Microchip IStaX web application enables an authenticated low-privileged user to exploit weak cookie authentication mechanisms. This flaw allows them to recover a shared per-device cookie secret from their own session cookie, subsequently forging a new cookie that grants administrative privileges. This issue affects IStaX versions prior to 2026.03, posing significant risks to system integrity.
Affected Version(s)
IStaX 0 < 2026.03
