CVE-2026-35038 is a medium-severity arbitrary prototype read vulnerability affecting Signal K Server versions prior to 2.24.0, a server application used on boats. This flaw allows a low-privileged authenticated user to bypass data isolation and extract internal functions and properties from the global prototype object, leading to unauthorized information disclosure. Rated with a CVSS score of 5.3, it has a network attack vector and low attack complexity, requiring only low privileges for exploitation. There is currently no public exploit code available, nor is it listed in CISA's KEV catalog or actively exploited, though it has garnered minimal community discussion since its recent publication.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.24.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.