Back to Labs
Security Advisory

CVE-2023-26261

About

In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.

Weakness (CWE):CWE-74

Rainforest analyst review

UBIKA WAAP Gateway/Cloud through 6.10 has a blind XPath injection that leads to an authentication bypass by hijacking another connected user's session. Unauthenticated and remote, an attacker manipulates XPath processing to lift a valid session and step into an authenticated context. The uncomfortable detail, as with other appliances in this batch, is that WAAP is a web application firewall, the control meant to shield everything behind it.

Perimeter security appliances are internet-facing by design and implicitly trusted, which makes an unauthenticated auth-bypass on one especially valuable, defeating the gatekeeper hands an attacker whatever the appliance was protecting. Named, versioned flaws on such devices tend to be folded into scanning and intrusion toolkits quickly because the payoff is disproportionate. The 9.8 reflects a genuine full-access outcome with no precondition to speak of.

Our angle is exposure-driven urgency plus session-integrity thinking. We prioritize any UBIKA WAAP unit reachable from the internet for the upgrade to 6.11.0 or the 6.5.6-patch15 line, and because the exploit steals live sessions, we would treat existing sessions as suspect, invalidating them after patching and watching for anomalous authenticated activity that predates the fix.

References

Related CVEs

Frequently asked questions

What is CVE-2023-26261?

In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.

How severe is CVE-2023-26261?

CVE-2023-26261 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2023-26261 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2023-26261?

Public advisories list the following as affected: waap cloud, waap gateway. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-26261?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email