---
id: CVE-2026-1758
title: "Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation.\n\nThis issue affects GateManager: 11.5;0, 11.4.625515072:0.\n\n\n\nFixed in Version 11.6 or\_11.4.626194074 and above"
summary: "Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation.\n\nThis issue affects GateManager: 11.5;0, 11.4.625515072:0.\n\n\n\nFixed in Version 11.6 or\_11.4.626194074 and above"
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'
cwe:
  - CWE-384
vendor: Secomea
product: GateManager
affected:
  - 'GateManager 11.5;0, 11.4.625515072:0'
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:30:42.730'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1758'
references:
  - url: 'https://www.secomea.com/support/cybersecurity-advisory/'
    label: VulnerabilityReporting@secomea.com
tags:
  - nvd
  - cve.org
epss: 0.00241
epssPercentile: 0.13576
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T12:22:57.694228Z'
ingestedAt: '2026-09-15T11:36:07.414Z'
---

## Overview

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation.

This issue affects GateManager: 11.5;0, 11.4.625515072:0.



Fixed in Version 11.6 or 11.4.626194074 and above

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
