CVE-2026-2336: Weak webstax_auth Cookie Authentication Allows Privilege Escalation
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2336?
CVE-2026-2336 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2026-2336?
To fix CVE-2026-2336, update Microchip IStaX to a version later than 2026.03 to mitigate the vulnerability.
Who is affected by CVE-2026-2336?
CVE-2026-2336 affects users of Microchip IStaX versions up to 2026.03.
What type of vulnerability is CVE-2026-2336?
CVE-2026-2336 is a privilege escalation vulnerability related to weak cookie authentication.
Can CVE-2026-2336 allow an unauthorized user to gain admin access?
Yes, CVE-2026-2336 allows an authenticated low-privileged user to forge an administrative cookie, enabling unauthorized access.