← Back
CWE-384

412 CVEs • Abstraction: Compound

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

JSON object

Loading...

CVEs (412)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Goauthentik
1Authentik
Jun 17, 2026
Mar 28, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the W...Show more
authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would not revoke the session and the session holder would continue to have access to authentik. authentik 2025.2.3 and 2024.12.4 fix this issue. Switching to the cache-based session storage until the authentik instance can be upgraded is recommended. This will however also delete all existing sessions and users will have to re-authenticate.Show less
-
-
Jun 17, 2026
Mar 11, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the...Show more
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and can read, modify and/or write new data. To gain authenticated sessions of other users, the attacker must invest considerable time and effort. This vulnerability has a high impact on the confidentiality and integrity of the application with no effect on the availability of the application.Show less
1Printerlogic
2Vasion Print
Virtual Appliance
Jun 17, 2026
Mar 5, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.
1Mattermost
1Mattermost Server
Jun 17, 2026
Feb 24, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions gran...Show more
Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.Show less
1Ibm
1Openpages With Watson
Jun 17, 2026
Feb 20, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is still left active after...Show more
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is still left active after logout.Show less
1Prasathmani
1Tiny File Manager
Jun 17, 2026
Feb 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
1Hcltech
1Dryice Iautomate
Jun 17, 2026
Feb 5, 2025
N/A· v4
6.0 MEDIUM· v3
N/A· v2
HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.
-
-
Jun 17, 2026
Jan 31, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.
-
-
Jun 17, 2026
Jan 30, 2025
9.3 CRITICAL· v4
N/A· v3
N/A· v2
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
-
-
Jun 17, 2026
Jan 30, 2025
5.3 MEDIUM· v4
N/A· v3
N/A· v2
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
-
-
Jun 17, 2026
Jan 28, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authentic...Show more
Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote attacker can access the victim's web panel with the same session identifier.Show less
1Youdiancms
1Youdiancms
Jun 17, 2026
Jan 27, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Jan 11, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Jan 11, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.
1Two Factor Authentication Project
1Two Factor Authentication
Jun 17, 2026
Jan 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.
-
-
Jun 17, 2026
Dec 30, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has been reported in versions 1.50.3 and prior where an attacker can copy the session cookie before a user...Show more
Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has been reported in versions 1.50.3 and prior where an attacker can copy the session cookie before a user logs out, potentially allowing session hijacking. Although the session token is replaced and invalidated upon logout, if an attacker manages to capture the session cookie before this process, they can use the token to gain unauthorized access to the user's session until the token expires or is manually cleared. This vulnerability hinges on the attacker's ability to access the session cookie during an active session, either through a man-in-the-middle attack, by exploiting another vulnerability like XSS, or via direct access to the victim's device. Although there is no direct resolution to this vulnerability, it is recommended to always use the latest version of Password Pusher to best mitigate risk. If self-hosting, ensure Password Pusher is hosted exclusively over SSL connections to encrypt traffic and prevent session cookies from being intercepted in transit. Additionally, implement best practices in local security to safeguard user systems, browsers, and data against unauthorized access.Show less
-
-
Jun 17, 2026
Dec 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP t...Show more
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Dec 12, 2024
9.3 CRITICAL· v4
5.3 MEDIUM· v3
N/A· v2
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version...Show more
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.Show less
1Abb
19Aspect Ent 12 Firmware
Aspect Ent 256 FirmwareAspect Ent 2 Firmware+16 more
Jun 17, 2026
Dec 5, 2024
9.3 CRITICAL· v4
10.0 CRITICAL· v3
N/A· v2
Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS...Show more
Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02Show less
1Chatwoot
1Chatwoot
Jun 17, 2026
Nov 15, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to pe...Show more
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker has obtained a session token.Show less