Executive brief
KTM System e-BOK is a web portal used by housing cooperative residents to manage personal data and view financial settlements. A security flaw in the login system allows attackers to make unlimited password guesses without being locked out. Because the system also restricts passwords to simple six-digit numbers, an attacker could quickly gain unauthorized access to resident accounts and sensitive financial information.
Technical details
The KTM System e-BOK web application suffers from an improper restriction of excessive authentication attempts (CWE-307). The application fails to implement rate-limiting, account lockout, or progressive delays on the login interface. This vulnerability is exacerbated by a related issue (CVE-2026-35097) that restricts user passwords to a six-digit numeric format. A remote, unauthenticated attacker can exploit this lack of throttling to perform a high-speed brute-force attack, successfully guessing the 1,000,000 possible password combinations in a short timeframe. The issue was addressed in a patch released in June 2026.
Affected products
- KTM System e-BOK All versions prior to June 2026 update
Timeline
- 2026-06-30: advisory: Advisory published by CERT.PL
- 2026-06-30: disclosed
- 2026-06-01: patched: Patch released in June 2026