Junglewise Threat Intelligence

CVE-2026-36829: Panabit PAP-XM320 authentication bypass in embedded HTTP server

CVE-2026-36829 · Severity: info · CVSS 9.8 · Published 2026-05-19

Technologies: Panabit PAP-XM320. Vendors: Panabit.

Executive brief

Panabit PAP-XM320 is a network management appliance used for traffic control and security auditing. A security flaw in its web management interface allows an attacker to bypass login requirements and gain full administrative access to the device. This could lead to unauthorized network monitoring, data interception, or complete disruption of the organization's internet connectivity.

Technical details

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 through version 7.7. The vulnerability stems from improper sanitization of user-controlled session cookies. The server validates sessions by performing a filesystem existence check using the cookie value as part of a file path. By supplying a specially crafted cookie containing directory traversal sequences (e.g., ../), an attacker can point the check to a known existing file on the system, tricking the server into treating the request as authenticated. This allows a remote, unauthenticated attacker to bypass security controls and access administrative functions.

Affected products

  • Panabit PAP-XM320 up to and including v7.7

Timeline

  • 2026-05-19: disclosed: Initial disclosure date

References

Related threats