# KTM System e-BOK patches four session flaws

Published: 2026-06-30 · Severity: medium
Canonical: https://vorant.io/reports/c2b5ac98-0ef4-5a55-9731-8eac1d9e9c1b/ktm-system-e-bok-patches-four-session-flaws

> CERT Polska coordinated fixes for four vulnerabilities in KTM System e-BOK allowing session fixation, CSRF, weak passwords, and brute-force attacks.

CERT Polska disclosed four vulnerabilities affecting KTM System e-BOK, a Polish customer self-service portal software, following a report from researcher Jacek Korta. The flaws span session management (CVE-2026-35095), where session identifiers can be fixed by an attacker prior to authentication and remain valid post-login, enabling session hijacking; and CSRF vulnerabilities (CVE-2026-35096) in email and password change functions that allow attackers to forge state-changing requests against authenticated users.

Compounding these issues, the application restricts passwords to six numeric digits only (CVE-2026-35097) and imposes no rate-limiting or lockout on login attempts (CVE-2026-35098). CERT Polska notes that combined, these two weaknesses are particularly severe since a six-digit numeric password space can be exhausted via brute force in a short time given unlimited authentication attempts. All four issues were addressed in a patch released in June 2026 through CERT Polska's coordinated vulnerability disclosure process.

This is a vendor-side disclosure of design and implementation flaws rather than an actively exploited threat; no in-the-wild exploitation is reported. Organizations using KTM System e-BOK should apply the June 2026 patch and review session and authentication configurations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35095, CVE-2026-35096, CVE-2026-35097, CVE-2026-35098

Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-35095

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c2b5ac98-0ef4-5a55-9731-8eac1d9e9c1b/ktm-system-e-bok-patches-four-session-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
