Junglewise Threat Intelligence

CVE-2026-35098: KTM System e-BOK improper rate limiting in login

CVE-2026-35098 · Severity: info · CVSS 6.9 · Published 2026-06-30

Technologies: KTM System e-BOK. Vendors: KTM System.

Executive brief

KTM System e-BOK is a web portal used by housing cooperative residents to manage personal data and view financial settlements. A security flaw in the login system allows attackers to make unlimited password guesses without being locked out. Because the system also restricts passwords to simple six-digit numbers, an attacker could quickly gain unauthorized access to resident accounts and sensitive financial information.

Technical details

The KTM System e-BOK web application suffers from an improper restriction of excessive authentication attempts (CWE-307). The application fails to implement rate-limiting, account lockout, or progressive delays on the login interface. This vulnerability is exacerbated by a related issue (CVE-2026-35097) that restricts user passwords to a six-digit numeric format. A remote, unauthenticated attacker can exploit this lack of throttling to perform a high-speed brute-force attack, successfully guessing the 1,000,000 possible password combinations in a short timeframe. The issue was addressed in a patch released in June 2026.

Affected products

  • KTM System e-BOK All versions prior to June 2026 update

Timeline

  • 2026-06-30: advisory: Advisory published by CERT.PL
  • 2026-06-30: disclosed
  • 2026-06-01: patched: Patch released in June 2026

References

Related threats