CVE-2026-51538
published 2026-07-13CVE-2026-51538: EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server…
PriorityP358critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.39%
32.8th percentile
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opener_project | opener | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
EIPStackGroup OpENer 2.3.0 Encapsulation access control
vuldb·2026-07-14
CVE-2026-51538 [LOW] EIPStackGroup OpENer 2.3.0 Encapsulation access control
A vulnerability labeled as problematic has been found in EIPStackGroup OpENer 2.3.0. This impacts an unknown function of the component Encapsulation Handler. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2026-51538. The attack may be performed from remote. There is no available exploit.
GHSA
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions.
ghsa_unreviewed·2026-07-14
CVE-2026-51538 [CRITICAL] CWE-284 EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions.
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-13
Published