CWE-384— Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.— MITRE CWE catalog
441 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-384page 9 of 9
- CVE-2026-23796CRITICALCVSS 9.8EG 9.82026-02-05
Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the auth…
- CVE-2026-24352CRITICALCVSS 9.8EG 9.82026-02-27
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authe…
- CVE-2026-24894HIGHCVSS 7.5EG 7.52026-02-12
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to…
- CVE-2026-25101CRITICALCVSS 9.8EG 9.82026-03-27
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticate…
- CVE-2026-30224MEDIUMCVSS 5.4EG 5.42026-03-06
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions when a user logs out. Although the browser cookie is cleared, the corresponding session rema…
- CVE-2026-30808HIGHCVSS 8.1EG 8.12026-05-12
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800
- CVE-2026-31940HIGHCVSS 7.5EG 7.52026-04-10
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session f…
- CVE-2026-33384MEDIUMCVSS 4.8EG 4.82026-05-29
QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authent…
- CVE-2026-33492HIGHCVSS 7.3EG 7.32026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session reg…
- CVE-2026-33757HIGHCVSS 8.3EG 8.32026-03-27
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker…
- CVE-2026-33946MEDIUMCVSS 5.9EG 5.92026-03-27
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a …
- CVE-2026-34454LOWCVSS 3.5EG 3.52026-04-14
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the …
- CVE-2026-35095MEDIUMCVSS 4.8EG 4.82026-06-30
KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value remains unchanged after successful login. This behaviour enables an attacker to fix a session I…
- CVE-2026-40010CRITICALCVSS 9.1EG 9.12026-05-06
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 …
- CVE-2026-40082MEDIUMCVSS 5.4EG 5.42026-06-25
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The …
- CVE-2026-41613HIGHCVSS 8.8EG 8.82026-05-12
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-41839MEDIUMCVSS 4.2EG 4.22026-06-09
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring …
- CVE-2026-43827MEDIUMCVSS 6.5EG 6.52026-05-25
Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes…
- CVE-2026-45773MEDIUMCVSS 6.5EG 6.52026-05-15
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was wai…
- CVE-2026-48545MEDIUMCVSS 6.8EG 6.82026-05-27
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint…
- CVE-2026-53900MEDIUMCVSS 4.3EG 4.32026-06-16
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability…
- CVE-2026-56224MEDIUMCVSS 5.4EG 5.42026-07-01
Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-contr…
- CVE-2026-56425HIGHCVSS 8.8EG 8.82026-06-22
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application…
- CVE-2026-59883MEDIUMCVSS 6.1EG 6.12026-07-08
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix mat…
- CVE-2026-61592HIGHCVSS 7.4EG 7.42026-09-16
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user…
- CVE-2026-64857MEDIUMCVSS 5.3EG 5.32026-09-09
tirreno, a security framework, has a session fixation issue in versions prior to 0.10.0. During authentication, tirreno validates the user's credentials and establishes the authenticated session, but it does not call `session_regenerate_id…
- CVE-2026-69214MEDIUMCVSS 6.8EG 6.82026-09-15
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejec…
- CVE-2026-69245MEDIUMCVSS 6.5EG 6.52026-08-03
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host,…
- CVE-2026-70594MEDIUMCVSS 6.7EG 6.72026-08-04
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vul…
- CVE-2026-75171CRITICALCVSS 9.8EG 9.82026-09-04
An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.
- CVE-2026-76196HIGHCVSS 7.4EG 7.42026-09-08
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attac…
- CVE-2026-77614HIGHCVSS 8.8EG 8.82026-09-17
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSE…
- CVE-2026-78428HIGHCVSS 8.0EG 8.02026-09-17
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
- CVE-2026-81181LOWCVSS 3.7EG 3.72026-09-18
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. …
- CVE-2026-81826CRITICALCVSS 9.1EG 9.12026-08-27
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an attacker already possesses a valid session—for example, from prior access or a stolen session token…
- CVE-2026-84652HIGHCVSS 7.3EG 7.32026-09-02
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known sessi…
- CVE-2026-85238MEDIUMCVSS 6.8EG 6.82026-09-03
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing sessi…
- CVE-2026-86279MEDIUMCVSS 6.3EG 6.32026-09-07
A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes sessi…
- CVE-2026-86674MEDIUMCVSS 6.3EG 6.32026-09-08
A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fixia…
- CVE-2026-86688HIGHCVSS 7.4EG 7.42026-09-17
Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication.Plug.Helpers.store…
- CVE-2026-92984HIGHCVSS 8.1EG 8.12026-09-17
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send v…
Map vulnerabilities like CWE-384 to your infrastructure
EchelonGraph correlates every CVE — across CWE-384 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →