VulnSea

CWE-384

CVEs classified under CWE-384, newest first.

29 CVEsRSS

CVE-2026-61687High· 7.1
yesterday

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

Twilighthatchet-dev · hatchetvia NVD
CVE-2026-82355Medium· 4.2
yesterday

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

SunlitApache Software Foundation · apache-airflowvia NVD
CVE-2026-81181Low· 3.7
4d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation…

SunlitSyslifters · sysreptorEPSS 0.22%via NVD
CVE-2026-86688High· 7.4
5d ago

Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication.Plug.Helpers.sto…

Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication.Plug.Helpers.sto…

Twilightteam-alembic · ash_authenticationEPSS 0.41%via NVD
CVE-2026-92984High· 8.1
5d ago

HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions

HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send…

Twilighthubzero · hubzero-cmsEPSS 0.26%via NVD
CVE-2026-77614High· 8.8PoC
5d ago

Opencast is a free, open-source platform to support the management of educational audio and video content

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected J…

Midnightopencast · opencastEPSS 0.40%via NVD
CVE-2026-78428High· 8.0
5d ago

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

Twilightgo · neuvectorEPSS 0.24%via NVD
CVE-2026-61592High· 7.4
6d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated us…

Twilightdjust-org · djustEPSS 0.29%via NVD
CVE-2026-69214Medium· 6.8
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejec…

Sunlithttp4s · http4sEPSS 0.26%via NVD
CVE-2026-1758High· 8.3
1w ago

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

TwilightSecomea · GateManagerEPSS 0.24%via NVD
CVE-2026-64857Medium· 5.3
1w ago

tirreno, a security framework, has a session fixation issue in versions prior to 0.10.0

tirreno, a security framework, has a session fixation issue in versions prior to 0.10.0. During authentication, tirreno validates the user's credentials and establishes the authenticated session, but it does not call `session_regenerate_…

Sunlittirrenotechnologies · tirrenoEPSS 0.27%via NVD
CVE-2026-86674Medium· 6.3PoC
2w ago

A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fix…

Twilightningzichun · Student Management SystemEPSS 0.22%via NVD
CVE-2026-76196High· 7.4
2w ago

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the att…

Twilightadobe · photoshop_mobileEPSS 0.20%via NVD
CVE-2026-86279Medium· 6.3PoC
2w ago

A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes ses…

TwilightSourceCodester · Syllabus-Aligned Learning Management & Examination SystemEPSS 0.23%via NVD
CVE-2026-75171Critical· 9.8
2w ago

An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.

An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.

MidnightEPSS 0.42%via NVD
CVE-2026-85238Medium· 6.8
2w ago

MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow

MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing ses…

Sunlitmisp-project · mispEPSS 0.22%via NVD
CVE-2026-84652High· 7.3
2w ago

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known ses…

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known ses…

Twilightjenkins · jenkinsEPSS 0.47%via NVD
CVE-2026-70594Medium· 6.7
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another v…

Sunlitghost · ghostEPSS 0.16%via NVD
CVE-2026-69245Medium· 6.5
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.14%via NVD
CVE-2026-16089Medium· 5.4
2mo ago

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept a…

Sunlitredhat · build_of_keycloakEPSS 0.18%via NVD
CVE-2026-59883Medium· 4.7
2mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix m…

Sunlitguzzlephp · guzzleEPSS 0.17%via NVD
CVE-2026-14609Medium· 5.6
2mo ago

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely.…

SunlitEPSS 0.40%via NVD
CVE-2026-13707High· 7.6
2mo ago

Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.

Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.

Twilightmediawiki · mediawikiEPSS 0.34%via NVD
GHSA-5qfp-32cf-69jhHigh· 8.8
2mo ago

SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers

SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers

Twilightsurrealdb · surrealdbvia GHSA
CVE-2023-50176Medium· 4.2
1y ago

A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.

A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.

Sunlitfortinet · fortiosEPSS 0.40%via NVD
CVE-2024-7341High· 7.1
2y ago

A session fixation issue was discovered in the SAML adapters provided by Keycloak

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an …

Twilightredhat · keycloakEPSS 0.85%via NVD
CVE-2024-23679Critical· 9.8
2y ago

Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue

Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.

Midnightenonic · xpEPSS 0.84%via NVD
CVE-2022-27305High· 8.8
4y ago

Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.

Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.

Twilightgibbonedu · gibbonEPSS 0.90%via NVD
CVE-2021-2351High· 8.3
5y ago

Vulnerability in the Advanced Networking Option component of Oracle Database Server

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network acc…

Twilightoracle · advanced_networking_optionEPSS 2.4%via NVD
CWE-384 vulnerabilities (CVEs) · VulnSea