Brute Force Vulnerability in KTM System e-BOK Platform
CVE-2026-35098
6.9MEDIUM
What is CVE-2026-35098?
KTM System e-BOK lacks a limit or timeout on consecutive login attempts, allowing attackers to execute unlimited authentication requests. This deficiency enables rapid brute-force attacks on user accounts. When combined with another vulnerability where passwords are restricted to a six-digit numeric format, the potential for unauthorized access significantly increases. To mitigate this risk, a patch was released in June 2026.
Affected Version(s)
e-BOK 0 < 06.2026
