# CVE-2026-22617

## Summary

- **CVE ID:** CVE-2026-22617
- **Severity:** MEDIUM
- **CVSS Score:** 5.7 (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N)
- **CWE:** CWE-614
- **Published:** Apr 16, 2026
- **Last Modified:** Apr 16, 2026

## Description

Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.

## Affected Products

- Eaton — IPP Software (0)

## References

- [CNA](https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1025.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._