CVE-2023-26261EPSS p53.0%
CVE-2023-26261CVE-2023-26261
ubikasec / waap_cloud
Description
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.84% probability of exploitation · percentile 53.0% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |