CVE-2026-33591: Tranquil It Systems Wapt Server

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

Affected products

Published 2026-08-03. Last modified 2026-09-01.