Junglewise Threat Intelligence

CVE-2026-35096: KTM System e-BOK CSRF in email and password change functions

CVE-2026-35096 · Severity: info · CVSS 5.1 · Published 2026-06-30

Technologies: KTM System e-BOK. Vendors: KTM System.

Executive brief

KTM System e-BOK is a web portal used by housing cooperatives to allow residents to view personal data, billing information, and manage their accounts. A security flaw allows an attacker to trick a logged-in user into visiting a malicious website that silently triggers a change to the user's email address or password. This could lead to unauthorized account takeover and access to the resident's private financial and housing records.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the KTM System e-BOK portal within the email and password update modules. The application fails to properly validate that requests are intentionally initiated by the authenticated user, such as through the use of anti-CSRF tokens. An attacker can exploit this by hosting a malicious page that submits a hidden POST request to the vulnerable endpoints when visited by a victim with an active session. Successful exploitation allows the attacker to change the victim's credentials or recovery email, leading to full account compromise. The issue was addressed in the June 2026 patch.

Affected products

  • KTM System e-BOK All versions prior to June 2026 update

Timeline

  • 2026-06-30: advisory: Advisory published by CERT.PL
  • 2026-06-30: disclosed
  • 2026-06: patched

References

Related threats