CVE-2026-19974 | treefrogframework treefrog-framework up to 2.11.2 Session Cookie tsessioncookiestore.cpp std::strncmp improper authentication (Issue 436)

SecurityVulns

A vulnerability was found in treefrogframework treefrog-framework up to 2.11.2. It has been declared as critical. This vulnerability affects the function std::strncmp of the file src/tsessioncookiestore.cpp of the component Session Cookie Handler. The manipulation results in improper authentication.

This vulnerability is reported as CVE-2026-19974. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure.VulDB Recent EntriesRead More