CWE-384

CWE-384 · 10 records · 9 with a public proof-of-concept

Records the NVD classes under CWE-384, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-92609

    Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J:…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-77614public PoC

    Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jse…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.1CVE-2026-92984public PoC

    HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8CVE-2026-78428public PoC

    For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.1CVE-2026-61687public PoC

    Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.8CVE-2026-79312public PoC

    webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation after authentication, so …

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 6.7CVE-2026-70594public PoC

    Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the sam…

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 4.3CVE-2026-95828public PoC

    A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead to session fixiation. It is possible to launch the…

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 4.2CVE-2026-57179public PoC

    Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using re…

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 4.2CVE-2026-82355public PoC

    When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request t…

    airflow

    AI risk analysis on Exploit-DB.ai →