CVE-2026-35096

MEDIUM

Cross-Site Request Forgery (CSRF) in KTM System e-BOK

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-35096. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-35096, a Cross-Site Request Forgery (CSRF) vulnerability in KTM System e-BOK's email-change and password-change functionalities. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation or technical details about the attack vectors.

Description

KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged POST request to the application. This allows the attacker to trigger an unauthorized email or password change on behalf of the victim without their knowledge or interaction. This issue was fixed in the patch published in June 2026.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-35096_ktm_system_e-bok.py

This repository contains an auto-generated stub module for CVE-2026-35096, a Cross-Site Request Forgery (CSRF) vulnerability in KTM System e-BOK's email-change and password-change functionalities. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation or technical details about the attack vectors.

Classification
Stub 99%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: KTM System e-BOK (unspecified version)
No auth needed
Prerequisites: Victim must be authenticated to KTM System e-BOK · Victim must visit attacker-controlled malicious website
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/06/CVE-2026-35095/

Scores

CVSS v4 5.1
EPSS 0.0016
EPSS Percentile 5.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
KTM System/e-BOK < 06.2026
Published Jun 30, 2026
Tracked Since Jun 30, 2026