# CVE-2026-35097

## Summary

- **CVE ID:** CVE-2026-35097
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-521
- **Published:** Jun 30, 2026
- **Last Modified:** Jun 30, 2026

## Description

KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters.

This issue was fixed in the patch published in June 2026.

## Affected Products

- KTM System — e-BOK (0)

## References

- [CNA](https://cert.pl/posts/2026/06/CVE-2026-35095/)
- [CNA](https://ktmsystem.pl/internetowe-biuro-obslugi-klienta/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.42%
- **EPSS Percentile:** 35.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._