CVE-2024-26331: Recrystallize Software Recrystallize Server

High severity, CVSS 7.5. EPSS: 51.3% chance of exploitation in the next 30 days.

ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. Attackers can bypass the authentication mechanism by modifying the cookie to contain an expected value.

Affected products

Published 2024-04-30. Last modified 2026-06-17.