CVE-2026-33591 PUBLISHED

Authentication bypass on WaptServer

Assigner: ENISA
Reserved: 23.03.2026 Published: 03.08.2026 Updated: 03.08.2026

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor Tranquil IT Systems
Product WAPT Server
Versions Default: unaffected
  • affected from 2.6.0.16767 to 2.6.1.17787 (incl.)

Credits

  • Brian CHERVY, System Engineer from Antiane, Réunion Team, https://antiane.com finder
  • CERT-FR coordinator

References

Problem Types

  • CWE-288 Authentication bypass using an alternate path or channel CWE