CVE-2022-36536
Critical · CVSS 9.8Syncovery 9 for Linux — Insecure Session Token Generation / Privilege Escalation
- CVSS
- 9.8
- nvd
- EPSS
- 5.20%
- 91th pct
- KEV
- No
- Class
- kernel local
- CWE-330
Description
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
Search profile — drives PoC discovery
Symbols post_applogin.phpsession tokenapploginprivilege escalationcrafted session tokens
Keywords CVE-2022-36536Syncoverypost_applogin.phpsession token privilege escalationSyncovery 9 Linux exploitCWE-330 Syncoverymgm-sp Syncovery vulnerabilities
Versions: <= 9.47x
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z