KTM System e-BOK patches four session flaws
CERT Polska coordinated fixes for four vulnerabilities in KTM System e-BOK allowing session fixation, CSRF, weak passwords, and brute-force attacks.
CERT Polska disclosed four vulnerabilities affecting KTM System e-BOK, a Polish customer self-service portal software, following a report from researcher Jacek Korta. The flaws span session management (CVE-2026-35095), where session identifiers can be fixed by an attacker prior to authentication and remain valid post-login, enabling session hijacking; and CSRF vulnerabilities (CVE-2026-35096) in email and password change functions that allow attackers to forge state-changing requests against authenticated users.
Compounding these issues, the application restricts passwords to six numeric digits only (CVE-2026-35097) and imposes no rate-limiting or lockout on login attempts (CVE-2026-35098). CERT Polska notes that combined, these two weaknesses are particularly severe since a six-digit numeric password space can be exhausted via brute force in a short time given unlimited authentication attempts. All four issues were addressed in a patch released in June 2026 through CERT Polska's coordinated vulnerability disclosure process.
This is a vendor-side disclosure of design and implementation flaws rather than an actively exploited threat; no in-the-wild exploitation is reported. Organizations using KTM System e-BOK should apply the June 2026 patch and review session and authentication configurations.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-35095
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free