---
cve: "CVE-2026-35097"
severity: "MEDIUM"
cvss: 6.9
epss: "25%"
vendor: "KTM System"
kev: false
exploited: false
published: "2026-06-30 14:16:26"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T22:32:36+02:00"
---

# CVE-2026-35097

> 6.9 MEDIUM

## Beschreibung

KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters.

This issue was fixed in the patch published in June 2026.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://cert.pl/posts/2026/06/CVE-2026-35095/>
- <https://ktmsystem.pl/internetowe-biuro-obslugi-klienta/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-35097) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
