CWE-384— Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.— MITRE CWE catalog
454 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-384page 1 of 10
- CVE-2026-102489CRITICALCVSS 9.8EG 9.8⚠ KEV2026-09-30
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the under…
- CVE-2025-63224CRITICALCVSS 10.0EG 10.02025-11-19
The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access …
- CVE-2025-63216CRITICALCVSS 10.0EG 10.02025-11-18
The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access…
- CVE-2024-11317CRITICALCVSS 10.0EG 10.02024-12-05
Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; …
- CVE-2024-38513CRITICALCVSS 10.0EG 10.02024-07-01
Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id valu…
- CVE-2021-20151CRITICALCVSS 10.0EG 10.02021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This al…
- CVE-2026-18527CRITICALCVSS 9.9EG 9.92026-08-28
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulner…
- CVE-2026-92609CRITICALCVSS 9.8EG 9.82026-09-25
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects…
- CVE-2026-75171CRITICALCVSS 9.8EG 9.82026-09-04
An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.
- CVE-2021-32088CRITICALCVSS 9.8EG 9.82026-07-27
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
- CVE-2025-67446CRITICALCVSS 9.8EG 9.82026-06-04
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an…
- CVE-2026-25101CRITICALCVSS 9.8EG 9.82026-03-27
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticate…
- CVE-2026-24352CRITICALCVSS 9.8EG 9.82026-02-27
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authe…
- CVE-2026-23796CRITICALCVSS 9.8EG 9.82026-02-05
Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the auth…
- CVE-2025-7015CRITICALCVSS 9.8EG 9.82026-01-29
Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fixation. This issue affects QR Menu: before s1.05.12.
- CVE-2025-59841CRITICALCVSS 9.8EG 9.82025-09-25
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated users can continue to access protected endpoints, such as /api/pr…
- CVE-2025-53102CRITICALCVSS 9.8EG 9.82025-07-29
Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn c…
- CVE-2025-52689CRITICALCVSS 9.8EG 9.82025-07-16
Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the…
- CVE-2025-53826CRITICALCVSS 9.8EG 9.82025-07-15
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that…
- CVE-2025-45949CRITICALCVSS 9.8EG 9.82025-04-28
A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows…
- CVE-2025-28242CRITICALCVSS 9.8EG 9.82025-04-18
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.
- CVE-2025-28238CRITICALCVSS 9.8EG 9.82025-04-18
Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.
- CVE-2022-40916CRITICALCVSS 9.8EG 9.82025-02-06
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
- CVE-2024-57052CRITICALCVSS 9.8EG 9.82025-01-27
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.
- CVE-2024-13279CRITICALCVSS 9.8EG 9.82025-01-09
Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.
- CVE-2024-8643CRITICALCVSS 9.8EG 9.82024-09-27
Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0.
- CVE-2024-23679CRITICALCVSS 9.8EG 9.82024-01-19
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
- CVE-2023-48929CRITICALCVSS 9.8EG 9.82023-12-08
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.
- CVE-2023-5309CRITICALCVSS 9.8EG 9.82023-11-07
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
- CVE-2023-42322CRITICALCVSS 9.8EG 9.82023-09-20
Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.
- CVE-2023-41012CRITICALCVSS 9.8EG 9.82023-09-05
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.
- CVE-2023-31498CRITICALCVSS 9.8EG 9.82023-05-11
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
- CVE-2023-28316CRITICALCVSS 9.8EG 9.82023-05-09
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a co…
- CVE-2021-36394CRITICALCVSS 9.8EG 9.82023-03-06
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
- CVE-2023-24456CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
- CVE-2023-24444CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
- CVE-2023-24427CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
- CVE-2022-31689CRITICALCVSS 9.8EG 9.82022-11-09
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
- CVE-2022-40293CRITICALCVSS 9.8EG 9.82022-10-31
The application was vulnerable to a session fixation that could be used hijack accounts.
- CVE-2022-3269CRITICALCVSS 9.8EG 9.82022-09-23
Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
- CVE-2022-38054CRITICALCVSS 9.8EG 9.82022-09-02
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
- CVE-2021-38869CRITICALCVSS 9.8EG 9.82022-04-27
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
- CVE-2022-22922CRITICALCVSS 9.8EG 9.82022-02-18
TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.
- CVE-2021-41553CRITICALCVSS 9.8EG 9.82021-10-05
In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user w…
- CVE-2021-39290CRITICALCVSS 9.8EG 9.82021-08-23
Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB37…
- CVE-2020-8434CRITICALCVSS 9.8EG 9.82020-05-19
Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBK…
- CVE-2020-11729CRITICALCVSS 9.8EG 9.82020-04-15
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
- CVE-2020-5543CRITICALCVSS 9.8EG 9.82020-03-16
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions or execute malware …
- CVE-2019-10158CRITICALCVSS 9.8EG 9.82020-01-02
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
- CVE-2019-18418CRITICALCVSS 9.8EG 9.82019-10-24
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
Map vulnerabilities like CWE-384 to your infrastructure
EchelonGraph correlates every CVE — across CWE-384 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →