CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-36536

Critical · CVSS 9.8

Syncovery 9 for Linux — Insecure Session Token Generation / Privilege Escalation

CVSS
9.8
nvd
EPSS
5.20%
91th pct
KEV
No
Class
kernel local
CWE-330

Description

An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.

Search profile — drives PoC discovery

Symbols post_applogin.phpsession tokenapploginprivilege escalationcrafted session tokens
Keywords CVE-2022-36536Syncoverypost_applogin.phpsession token privilege escalationSyncovery 9 Linux exploitCWE-330 Syncoverymgm-sp Syncovery vulnerabilities
Versions: <= 9.47x

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z