CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
416 vulnerabilities with CWE-384
CVE-2026-16496
HIGH
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
CVSS 8.9
CVE-2026-16089
MEDIUM
Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session
CVSS 5.4
CVE-2026-59883
MEDIUM
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
CVSS 4.7
CVE-2026-14609
MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation
CVSS 5.6
CVE-2026-13707
HIGH
Session fixation attacks on improperly configured OAuth 1.0a tools
CVSS 7.6
CVE-2026-56224
MEDIUM
Capgo - Login CSRF and Session Fixation via URL Query Parameters
CVSS 5.4
CVE-2026-35095
MEDIUM
Session fixation in KTM System e-BOK
CVE-2026-40082
MEDIUM
Cacti: Session Fixation via missing session_regenerate_id() after login
CVSS 5.4
CVE-2026-56425
HIGH
MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection
CVSS 8.8
CVE-2026-12581
HIGH
Digiwin|EasyFlow .NET - Session Fixation
CVSS 7.5
CVE-2026-53900
MEDIUM
Cookie injection was possible when opening a PDF link
CVSS 4.3
CVE-2026-41839
MEDIUM
Spring Framework Escalation via Session Fixation in WebFlux
CVSS 4.2
CVE-2026-11335
MEDIUM
tittuvarghese CollegeManagementSystem login-form.php session_start session fixiation
CVSS 6.3
CVE-2026-33384
MEDIUM
Session Fixation in QuickCMS
CVE-2026-48545
MEDIUM
Gradio < 6.15.0 Cookie Injection via Shared Proxy Client
CVSS 6.8
CVE-2026-43827
MEDIUM
Apache Shiro: Session fixation: new session is not created after login by default
CVSS 6.5
CVE-2026-45773
MEDIUM
Turborepo: Login callback CSRF/session fixation
CVSS 6.5
CVE-2026-41613
HIGH
Visual Studio Code Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-30808
HIGH
Pandora FMS 777-800 - Session Fixation via Crafted Session ID
CVSS 8.1
CVE-2026-40010
CRITICAL
Apache Wicket: possible session fixation using AuthenticatedWebSession
CVSS 9.1
CVE-2026-34454
LOW
OAuth2 Proxy: Session cookie not cleared when rendering sign-in page
CVSS 3.5
CVE-2026-31940
HIGH
Session Fixation in Chamilo LMS
CVSS 7.5
CVE-2026-33946
MEDIUM
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
CVSS 5.9
CVE-2026-33757
CRITICAL
OpenBao lacks user confirmation for OIDC direct callback mode
CVSS 9.6
CVE-2026-25101
CRITICAL
Session Fixation in Bludit
CVSS 9.8
Details
Vulnerabilities
416