Description
A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file psi-probe-core/src/main/java/psiprobe/controllers/sessions/RemoveSessAttributeController.java of the component Session Attribute Handler. Performing a manipulation results in improper access controls. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-02-26
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Access Control Bypass
Action: Assess Impact
AI Analysis

Impact

The vulnerability lies in the Session Attribute Handler component of PSI Probe, specifically within the RemoveSessAttributeController. An attacker can manipulate the removal of session attributes, leading to unauthorized access or privilege escalation. This flaw is caused by improper access controls and is identified as CWE-266 and CWE-284.

Affected Systems

Psi‑Probe PSI Probe versions up to 5.3.0 are affected. The flaw is located in psi-probe-core/src/main/java/psiprobe/controllers/sessions/RemoveSessAttributeController.java and applies to any deployment using the Session Attribute Handler in those releases.

Risk and Exploitability

The CVSS base score of 5.3 indicates a medium severity, while the EPSS score of less than 1 percent reflects a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely with publicly available code, but no further exploitation prerequisites are documented beyond the manipulation of the controller’s access controls.

Generated by OpenCVE AI on April 16, 2026 at 15:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update or upgrade to a version of PSI Probe that includes the fix for the RemoveSessAttributeController access control issue.
  • If an immediate update is not possible, restrict or block access to the RemoveSessAttributeController endpoint using firewall rules, reverse proxy configuration, or application‑level URL filtering to prevent unauthorized requests.
  • Modify the application’s session management code to enforce strict authentication and authorization checks before allowing session attribute removal, ensuring only privileged users can perform such actions.
  • Monitor application logs for unexpected session attribute deletions and review any anomalous activity that might indicate exploitation.

Generated by OpenCVE AI on April 16, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 12 Mar 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:psi-probe:psi_probe:*:*:*:*:*:*:*:*

Fri, 27 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Psi-probe
Psi-probe psi Probe
Vendors & Products Psi-probe
Psi-probe psi Probe

Thu, 26 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file psi-probe-core/src/main/java/psiprobe/controllers/sessions/RemoveSessAttributeController.java of the component Session Attribute Handler. Performing a manipulation results in improper access controls. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title psi-probe PSI Probe Session Attribute RemoveSessAttributeController.java access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Psi-probe Psi Probe
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-27T17:27:38.521Z

Reserved: 2026-02-26T15:13:33.692Z

Link: CVE-2026-3268

cve-icon Vulnrichment

Updated: 2026-02-27T17:27:27.110Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-26T23:16:38.337

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-3268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T16:00:13Z

Weaknesses