← Back to browse · API

CVE-2026-33591

Severity
CRITICAL
CVSS
10.0
EPSS
0.00523
Risk score
40.18
CISA KEV
No
PoC
No
Published
2026-08-03
Modified
2026-08-03
First seen
2026-08-05
Aliases
EUVD-2026-52256, GHSA-JJ6F-HXJ9-R997
Products
Tranquil IT Systems:WAPT Server 2.6.0.16767 ≤2.6.1.17787
Sources
nvd CVE-2026-33591
euvd EUVD-2026-52256

Description

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

References