SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-9033

MEDIUM · CVSS 4.3 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-11

CyberRota Analysis

AI-Generated

Devices with a vulnerable captive portal service can be exploited by unauthenticated attackers who have network access, allowing them to terminate active sessions for specific users or clear all sessions entirely. This results in temporary service disruption, forcing users to re-authenticate to regain access. Organizations utilizing such devices should prioritize addressing this vulnerability to maintain user access and service continuity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9033
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.  Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.

Related CVEs

Other vulnerabilities affecting the same vendor(s)