CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

416 vulnerabilities with CWE-384
CVE-2026-16496 HIGH
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
CVSS 8.9
CVE-2026-16089 MEDIUM
Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session
CVSS 5.4
CVE-2026-59883 MEDIUM
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
CVSS 4.7
CVE-2026-14609 MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation
CVSS 5.6
CVE-2026-13707 HIGH
Session fixation attacks on improperly configured OAuth 1.0a tools
CVSS 7.6
CVE-2026-56224 MEDIUM
Capgo - Login CSRF and Session Fixation via URL Query Parameters
CVSS 5.4
CVE-2026-35095 MEDIUM
Session fixation in KTM System e-BOK
CVE-2026-40082 MEDIUM
Cacti: Session Fixation via missing session_regenerate_id() after login
CVSS 5.4
CVE-2026-56425 HIGH
MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection
CVSS 8.8
CVE-2026-12581 HIGH
Digiwin|EasyFlow .NET - Session Fixation
CVSS 7.5
CVE-2026-53900 MEDIUM
Cookie injection was possible when opening a PDF link
CVSS 4.3
CVE-2026-41839 MEDIUM
Spring Framework Escalation via Session Fixation in WebFlux
CVSS 4.2
CVE-2026-11335 MEDIUM
tittuvarghese CollegeManagementSystem login-form.php session_start session fixiation
CVSS 6.3
CVE-2026-33384 MEDIUM
Session Fixation in QuickCMS
CVE-2026-48545 MEDIUM
Gradio < 6.15.0 Cookie Injection via Shared Proxy Client
CVSS 6.8
CVE-2026-43827 MEDIUM
Apache Shiro: Session fixation: new session is not created after login by default
CVSS 6.5
CVE-2026-45773 MEDIUM
Turborepo: Login callback CSRF/session fixation
CVSS 6.5
CVE-2026-41613 HIGH
Visual Studio Code Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-30808 HIGH
Pandora FMS 777-800 - Session Fixation via Crafted Session ID
CVSS 8.1
CVE-2026-40010 CRITICAL
Apache Wicket: possible session fixation using AuthenticatedWebSession
CVSS 9.1
CVE-2026-34454 LOW
OAuth2 Proxy: Session cookie not cleared when rendering sign-in page
CVSS 3.5
CVE-2026-31940 HIGH
Session Fixation in Chamilo LMS
CVSS 7.5
CVE-2026-33946 MEDIUM
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
CVSS 5.9
CVE-2026-33757 CRITICAL
OpenBao lacks user confirmation for OIDC direct callback mode
CVSS 9.6
CVE-2026-25101 CRITICAL
Session Fixation in Bludit
CVSS 9.8
Details
Vulnerabilities 416