CVE-2026-51538: Critical severity EIPStackGroup OpENer vulnerability
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided sessionhandle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-51538?
CVE-2026-51538 has a critical severity score of 9.1.
How does CVE-2026-51538 exploit access control?
CVE-2026-51538 exploits access control by improperly handling encapsulation sessions, allowing unauthorized commands to be processed.
What systems are affected by CVE-2026-51538?
CVE-2026-51538 affects EIPStackGroup OpENer version 2.3.0.
How can I mitigate CVE-2026-51538?
To mitigate CVE-2026-51538, upgrade to a patched version of EIPStackGroup OpENer as soon as it becomes available.
What types of vulnerabilities does CVE-2026-51538 include?
CVE-2026-51538 includes Incorrect Access Control vulnerabilities affecting session handling.