CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-51538

criticalCVSS 9.1covered by 1 sourcefirst seen 2026-07-13
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.

⚡ Watch CVE-2026-51538

Get an email if CVE-2026-51538 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-51538

CVE.org record

Embed the live status

CVE-2026-51538 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-51538 status](https://www.csirts.com/badge/CVE-2026-51538)](https://www.csirts.com/cve/CVE-2026-51538)