GHSA-v47p-q5xc-j34wHighCVSS 8.8

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged...

Published
April 16, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.

🔗 References (3)