CVE-2026-33591

Tranquil IT Systems · WAPT Server

A critical authentication bypass vulnerability in WAPT Server allows remote, unauthenticated attackers to forge session tokens via specially crafted packets.

Executive summary

A critical authentication bypass vulnerability in Tranquil IT Systems WAPT Server allows unauthenticated attackers to gain full system access, posing a severe risk to organizational infrastructure.

Vulnerability

The software suffers from an authentication bypass (CWE-288) that enables unauthenticated remote attackers to retrieve valid session tokens for any account. This flaw occurs due to improper security restrictions during packet processing.

Business impact

Successful exploitation of this vulnerability allows an attacker to impersonate any user, including administrative accounts, leading to complete compromise of the WAPT Server environment. Given the CVSS score of 10.0, this represents the highest level of risk, potentially allowing attackers to deploy arbitrary software across the managed fleet, exfiltrate sensitive data, or disrupt business operations entirely.

Remediation

Immediate Action: Upgrade all instances of WAPT Server to version 2.6.1.17813 or later immediately to resolve the authentication flaw.

Proactive Monitoring: Review authentication and session management logs for unusual login patterns or multiple successful logins originating from unexpected IP addresses.

Compensating Controls: Implement strict network segmentation to restrict access to the WAPT Server management interface to known, trusted management segments only until patching is completed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability cannot be overstated. Administrators must prioritize the deployment of the vendor-provided patch to version 2.6.1.17813 immediately. Failure to address this flaw leaves the entire managed infrastructure susceptible to total takeover by external actors.