Critical severity9.1NVD Advisory· Published Jul 13, 2026· Updated Aug 11, 2026
CVE-2026-51538
CVE-2026-51538
Description
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:opener_project:opener:2.3.0:*:*:*:*:*:*:*
- Range: = 2.3.0
Patches
Vulnerability mechanics
References
2- github.com/EIPStackGroup/OpENer/issues/565nvdExploitIssue TrackingVendor Advisory
- gist.github.com/MrAlaskan/8156ca3acd6754a9f66efede0a1351f2nvdThird Party Advisory
News mentions
0No linked articles in our index yet.