CVE-2026-4827
CWE-331: Insufficient entropy enables session hijacking over the network.
Is CVE-2026-4827 being exploited?
Not confirmed. CVE-2026-4827 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.31% probability of exploitation in the next 30 days.
How severe is CVE-2026-4827?
CVE-2026-4827 is rated High with a CVSS score of 8.7. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-4827?
Not known from our data. No patch reference has been recorded for CVE-2026-4827, which is not the same as no patch existing — a fix may have shipped without a tagged reference, or after this record was written. The vendor advisory is the only authority on whether a fix exists, and mitigations may be available regardless.
What should I do about CVE-2026-4827?
Improve entropy; rotate tokens; apply patch when released.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Attacker could hijack active sessions by guessing/predicting tokens due to weak entropy in session management.
Patch when available
- affectedVersion 1.1.17 and prior
- affectedVersions D6.x
- affectedVersions D7.33 and prior
- affectedP139 version prior to P139.678.700
- affectedP437 version prior to P437.678.700
- affectedP439 version prior to P439.678.700
- affectedP532 version prior to P532.678.700
- affectedP539 version prior to P539.678.700
- affectedP631 version prior to P631.678.700
- affectedP632 version prior to P632.678.700
- affectedP633 version prior to P633.678.700
- affectedP634 version prior to P634.678.700
- affectedP633 version P633.680.700 only
- affectedP634 version P634.680.700 only
- affectedP138 version prior to P138.677.700
- affectedP436 version prior to P436.677.701
- affectedP438 version prior to P438.677.701
- affectedP638 version prior to P638.677.700
- affectedC434 version prior to C434.679.700
- affectedSeries model numbers with Protocol Option bit as G, H or L and all firmware versions
- affectedVersion 11.06.30 and prior
- affectedVersion 6.4.616.200.100 and prior
- affectedVersion 3.0.3 and prior
- affectedVersion 2022 CU6 and prior
- affectedVersion 2024 CU2 and prior
- affectedVersion 64.2025.0.13 and prior
- affectedV02.502.103 and prior
- affectedV02.002.002 and prior
- affectedVersion 2.9.4 and prior
- affectedVersion 11.08.02 and prior
- affectedVersion 11.06.36 and prior
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.