Description
A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass
security restriction using a specially crafted packet and retrieve a valid
session token for the targeted account.
Published: 2026-08-03
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Tranquil IT Systems' WAPT Server versions earlier than 2.6.1.17813 allows a remote unauthenticated attacker to bypass authentication controls. By sending a specially crafted packet, the server issues a valid session token for the targeted account, effectively hijacking that account’s session. This results in the attacker gaining all privileges associated with the victim account. Based on the description, it is inferred that the attacker can perform actions as the victim without needing to obtain or guess credentials. The flaw reflects a typical CWE‑288 weakness involving improper validation of authentication packets.

Affected Systems

The affected system is the WAPT Server from Tranquil IT Systems. Any installation running a version prior to 2.6.1.17813 is vulnerable. Organizations should verify their server version and assess whether they remain exposed.

Risk and Exploitability

The CVSS score of 10 indicates critical severity, with no authentication required and a remote attack vector. EPSS data is not available, and the issue is not listed in CISA KEV; however, the nature of the bypass strongly suggests ample motivation for attackers who can discover the packet. The likely attack vector is over the network to the WAPT Server’s management or API endpoints. Because the vulnerability is accessible remotely and requires no pre‑existing credentials, the risk to exposed deployments is high, warranting immediate remediation to prevent credential theft and potential lateral movement.

Generated by OpenCVE AI on August 4, 2026 at 21:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WAPT Server to version 2.6.1.17813 or newer, which contains the authentication bypass fix.
  • Restart the WAPT Server service to ensure the patched version is running and to clear any cached session data.
  • Restrict network access to the WAPT Server’s management interface and API, allowing connections only from trusted administrative hosts or internal networks until the patch is fully deployed.

Generated by OpenCVE AI on August 4, 2026 at 21:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Tranquil It Systems
Tranquil It Systems wapt Server
Vendors & Products Tranquil It Systems
Tranquil It Systems wapt Server

Mon, 03 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.
Title Authentication bypass on WaptServer
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Tranquil It Systems Wapt Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published:

Updated: 2026-08-03T10:51:35.202Z

Reserved: 2026-03-23T12:53:47.475Z

Link: CVE-2026-33591

cve-icon Vulnrichment

Updated: 2026-08-03T10:51:30.428Z

cve-icon NVD

Status : Received

Published: 2026-08-03T10:16:28.610

Modified: 2026-08-03T12:16:26.317

Link: CVE-2026-33591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:15:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel