Description
KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value remains unchanged after successful login. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session.

This issue was fixed in the patch published in June 2026.
Published: 2026-06-30
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

KTM System e‑BOK accepts a cookie from the client that contains a session identifier before the user is authenticated. The cookie, if it contains a valid name, is preserved after a successful login, allowing an attacker who has set that cookie to hijack the session of the authenticated user. This is a classic session‑fixation flaw (CWE‑384) and provides a path to unauthorized account access but does not allow code execution or data modification outside the hijacked session.

Affected Systems

The vulnerability is present in all releases of KTM System e‑BOK before the June 2026 patch. No precise version numbers are listed in the advisory, so any older deployment of the online client service portal is potentially affected.

Risk and Exploitability

The CVSS score of 4.8 denotes moderate severity, reflecting the requirement for user authentication to exploit the fault. The EPSS score is not available, so evidence of exploitation frequency is unknown, yet session‑fixation attacks are well known and can be automated against publicly reachable sites. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to trick a victim into visiting the site or otherwise having the attacker set the session cookie before login; after the victim logs in, the attacker can use the unchanged cookie to gain access to the victim’s account.

Generated by OpenCVE AI on June 30, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the June 2026 patch released by KTM System to fix the session‑fixation flaw.
  • Reconfigure the application to reject any session‑ID cookie that is supplied before a successful authentication and to generate a fresh session identifier after login.
  • Invalidate all current session cookies and enforce a logout for all users until the patch and configuration changes are in place.

Generated by OpenCVE AI on June 30, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Ktm System
Ktm System e-bok
Vendors & Products Ktm System
Ktm System e-bok

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value remains unchanged after successful login. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in the patch published in June 2026.
Title Session fixation in KTM System e-BOK
Weaknesses CWE-384
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ktm System E-bok
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-06-30T14:42:45.383Z

Reserved: 2026-04-01T13:05:10.153Z

Link: CVE-2026-35095

cve-icon Vulnrichment

Updated: 2026-06-30T14:42:40.285Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T10:01:30Z

Weaknesses