A AegiFlow
CRITICALCVSS 10.0

CVE-2026-33591

CVE-2026-33591 updated by NVD

Published
2026-08-03
Modified
2026-09-03
Sources
euvd, nvd

Summary

A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

References

Includes data from the ENISA EU Vulnerability Database (EUVD).

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.