PSIRT-123: IStaX Privilege Escalation via Weak Cookie Authentication
Vulnerability Details
Date of Disclosure: 04/14/2026
Affected Product:IStaX (VSC6817)
Vulnerability Type: Privilege escalation
CVE Identifier: CVE-2026-2336
CVSS Score: 8.7
Vulnerability Description:
The web management interface uses a webstax_auth cookie design that allows a low-privileged authenticated user to recover a shared per-device secret from their own session cookie and forge a new cookie with administrative privileges
Successful exploitation can grant full administrator access to the device web interface without following the normal login flow, reducing audit visibility and allowing unauthorized configuration changes or service disruption.
Version 2026.03 updates the authentication cookie handling so low-privileged users can no longer derive a reusable shared secret and forge higher-privilege cookies.
{"SalesForceSecurePath":"https://microchip.my.salesforce-scrt.com","EmbeddedServiceName":"Messaging_For_Microchip","SalesForcePath":"https://microchip.my.site.com/ESWMessagingForMicrochi1755319480924","AgentAvailableHeader":"No problem. Chat with our engineering experts or schedule a call that's convenient for you.","ScheduleCallUrl":"https://microchip.my.site.com/schedulemeetingportal/s/","SalesforceOrgId":"00Do0000000KAkK","JsUrl":"https://microchip.my.site.com/ESWMessagingForMicrochi1755319480924/assets/js/bootstrap.min.js"}