CVE-2026-33591: Tranquil It Systems Wapt Server
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.
Affected products
- Tranquil It Systems Wapt Server: from 2.6.0.16767, up to and including 2.6.1.17787
Published 2026-08-03. Last modified 2026-09-01.