CVE-2026-35096
MEDIUMCross-Site Request Forgery (CSRF) in KTM System e-BOK
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-35096. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-35096, a Cross-Site Request Forgery (CSRF) vulnerability in KTM System e-BOK's email-change and password-change functionalities. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation or technical details about the attack vectors.
Description
KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged POST request to the application. This allows the attacker to trigger an unauthorized email or password change on behalf of the victim without their knowledge or interaction. This issue was fixed in the patch published in June 2026.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-35096, a Cross-Site Request Forgery (CSRF) vulnerability in KTM System e-BOK's email-change and password-change functionalities. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation or technical details about the attack vectors.
References (2)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X