
CVE-2026-34917 Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An atta… https://www.cve.org/CVERecord?id=CVE-2026-34917
Post summary
The text reports that low‑privileged session IDs from the web admin console can be reused in the XML‑RPC API, potentially allowing privilege escalation.

