CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.