CVE-2026-34917
Last modified
CVE-2026-34917 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably.
Metrics
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-34917?
How severe is CVE-2026-34917?
How do I fix CVE-2026-34917?
Are you affected by CVE-2026-34917?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
