CVE detail
CVE-2026-33591
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 3
- within the 30d window
- Peak daily
- 3
- highest bucket
Evidence
Source links by recency
3 source links · newest first
No excerpt available.
referencewww.wapt.frAug 3, 2026, 10:16 AMNo excerpt available.
referencewww.wapt.frAug 3, 2026, 10:16 AMNo excerpt available.
referencewww.wapt.frAug 3, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-72691CVSS 7.5 · High
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arb…
- CVE-2026-66451CVSS 6.5 · Medium
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
- CVE-2026-66425CVSS 6.5 · Medium
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.
- CVE-2026-65542CVSS 8.8 · High
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
- CVE-2026-24254CVSS 9.8 · Critical
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerabili…
- CVE-2026-58073CVSS 9.5 · Critical
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.