CWE-384— Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.— MITRE CWE catalog
454 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-384page 2 of 10
- CVE-2019-5523CRITICALCVSS 9.8EG 9.82019-04-01
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious actor to access the T…
- CVE-2018-18926CRITICALCVSS 9.8EG 9.82018-11-04
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.
- CVE-2018-18925CRITICALCVSS 9.8EG 9.82018-11-04
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/s…
- CVE-2016-6545CRITICALCVSS 9.8EG 9.82018-07-13
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be ter…
- CVE-2018-12071CRITICALCVSS 9.8EG 9.82018-06-17
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.
- CVE-2018-11714CRITICALCVSS 9.8EG 9.82018-06-04
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cg…
- CVE-2018-6959CRITICALCVSS 9.8EG 9.82018-04-13
VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.
- CVE-2017-15304CRITICALCVSS 9.8EG 9.82017-10-15
/bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after…
- CVE-2016-10405CRITICALCVSS 9.8EG 9.82017-09-07
Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.
- CVE-2017-12873CRITICALCVSS 9.8EG 9.82017-09-01
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is …
- CVE-2017-12868CRITICALCVSS 9.8EG 9.82017-09-01
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing c…
- CVE-2017-12965CRITICALCVSS 9.8EG 9.82017-08-23
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
- CVE-2015-1820CRITICALCVSS 9.8EG 9.82017-08-09
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
- CVE-2015-1174CRITICALCVSS 9.8EG 9.82017-08-02
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.
- CVE-2016-9125CRITICALCVSS 9.8EG 9.82017-03-28
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, …
- CVE-2015-4594CRITICALCVSS 9.8EG 9.82017-01-10
eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.
- CVE-2021-42761CRITICALCVSS 9.0EG 9.82023-02-16
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow …
- CVE-2022-40630CRITICALCVSS 6.5EG 9.82022-09-23
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interfac…
- CVE-2021-46279CRITICALCVSS 5.8EG 9.82022-10-24
Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attacks against users. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
- CVE-2019-7747CRITICALCVSS 9.6EG 9.62019-02-11
DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.
- CVE-2026-92414CRITICALCVSS 9.3EG 9.32026-10-07
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no cre…
- CVE-2025-24503CRITICALCVSS 9.3EG 9.32025-01-30
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
- CVE-2007-4188HIGHCVSS v2 9.3EG 9.32007-08-08
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.
- CVE-2026-81826CRITICALCVSS 9.1EG 9.12026-08-27
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an attacker already possesses a valid session—for example, from prior access or a stolen session token…
- CVE-2009-10007CRITICALCVSS 9.1EG 9.12026-06-09
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a …
- CVE-2026-40010CRITICALCVSS 9.1EG 9.12026-05-06
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 …
- CVE-2025-69602CRITICALCVSS 9.1EG 9.12026-01-28
A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users lo…
- CVE-2025-45953CRITICALCVSS 9.1EG 9.12025-04-28
A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable re…
- CVE-2025-27661CRITICALCVSS 9.1EG 9.12025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.
- CVE-2023-52268CRITICALCVSS 9.1EG 9.12024-11-12
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freesco…
- CVE-2024-23590CRITICALCVSS 9.1EG 9.12024-11-04
Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.
- CVE-2022-36437CRITICALCVSS 9.1EG 9.12022-12-29
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are …
- CVE-2020-12258CRITICALCVSS 9.1EG 9.12020-05-18
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256…
- CVE-2020-9370CRITICALCVSS 9.1EG 9.12020-03-05
HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
- CVE-2020-8990CRITICALCVSS 9.1EG 9.12020-02-20
Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
- CVE-2016-8638CRITICALCVSS 9.1EG 9.12017-07-12
A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an…
- CVE-2017-3968CRITICALCVSS 7.5EG 9.12018-06-13
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or man…
- CVE-2026-16496HIGHCVSS 8.9EG 8.92026-07-28
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using t…
- CVE-2026-77614HIGHCVSS 8.8EG 8.82026-09-17
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSE…
- CVE-2026-78428HIGHCVSS 8.8EG 8.82026-09-17
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
- CVE-2026-56425HIGHCVSS 8.8EG 8.82026-06-22
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application…
- CVE-2026-41613HIGHCVSS 8.8EG 8.82026-05-12
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-7014HIGHCVSS 8.8EG 8.82026-01-29
Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affects Menu Panel: through 29012026. NOTE: The vendor was contacted early about this disclosure but did not respond in an…
- CVE-2026-22082HIGHCVSS 8.8EG 8.82026-01-09
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could explo…
- CVE-2023-53776HIGHCVSS 8.8EG 8.82025-12-10
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identifiers. Attackers can issue unauthorized requests to the device management API b…
- CVE-2025-63529HIGHCVSS 8.8EG 8.82025-12-01
A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to u…
- CVE-2025-56400HIGHCVSS 8.8EG 8.82025-11-24
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the S…
- CVE-2025-10228HIGHCVSS 8.8EG 8.82025-10-14
Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affects Agentis: before 4.44.
- CVE-2025-53895HIGHCVSS 8.8EG 8.82025-07-15
ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a ses…
- CVE-2024-13967HIGHCVSS 8.8EG 8.82025-06-04
This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by the integrated web Server of EIBPORT. This issue affects EIBPORT V3 KNX: through 3.9.8; EIBPORT V3 KNX GSM: through 3.…
Map vulnerabilities like CWE-384 to your infrastructure
EchelonGraph correlates every CVE — across CWE-384 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →