Session Management Vulnerability in KTM System e-BOK
CVE-2026-35095
4.8MEDIUM
What is CVE-2026-35095?
The KTM System e-BOK application has a vulnerability that allows clients to set session identifiers prior to user authentication. This issue arises from the fact that a cookie with a valid name retains its value even after the user successfully logs in. Consequently, an attacker can manipulate the session ID for a targeted user, allowing them to hijack an authenticated session and gain unauthorized access to sensitive user data. This significant security flaw was addressed in a patch released in June 2026.
Affected Version(s)
e-BOK 0 < 06.2026
