CVE-2026-36829

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled cookie value without proper sanitization, allowing directory traversal and bypass of authentication.
Configurations

No configuration.

History

24 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de omisión de autenticación en el servidor HTTP embebido de Panabit PAP-XM320 hasta la versión 7.7 inclusive. El servidor valida las cookies de sesión utilizando una comprobación de existencia en el sistema de archivos basada en un valor de cookie controlado por el usuario sin una sanitización adecuada, lo que permite el salto de directorio y la omisión de autenticación.

19 May 2026, 18:16

Type Values Removed Values Added
References () https://secreu.notion.site/CVE-2026-36829-3652c0ab461580e19704e87b18865714 - () https://secreu.notion.site/CVE-2026-36829-3652c0ab461580e19704e87b18865714 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-22
CWE-287

19 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 17:16

Updated : 2026-07-24 12:10


NVD link : CVE-2026-36829

Mitre link : CVE-2026-36829

CVE.ORG link : CVE-2026-36829


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-287

Improper Authentication