Threats Tagged 'cve-2026-24667'
View all threats tagged with 'cve-2026-24667'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-24667'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-24667 is a medium-severity vulnerability in the Open eClass platform versions prior to 4.2, where active user sessions are not invalidated after a password change. This insufficient session expiration (CWE-613) allows attackers who have access to existing session tokens to maintain unauthorized access even after the user updates their password. The vulnerability does not require user interaction but does require low privileges and has a network attack vector with high attack complexity. It impacts confidentiality, integrity, and availability to a limited extent. The issue has been patched in version 4.2, and no known exploits are currently reported in the wild. European organizations using Open eClass should prioritize upgrading to the patched version to mitigate risks associated with session hijacking post-password change. Join the discussion | CVE Database V5 | 02/03/2026, 16:59:32 UTC Added: 02/04/2026, 08:01:28 UTC |
Showing 1 to 1 of 1 result