CVE-2026-27933

MEDIUM

Manyfold <0.133.0 - Session Hijack

Title source: llm
STIX 2.1

Description

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via cookie leakage in proxy caches. Version 0.133.0 fixes the issue.

Scores

CVSS v3 6.8
EPSS 0.0005
EPSS Percentile 14.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-613
Status published
Products (1)
manyfold/manyfold < 0.133.0
Published Feb 26, 2026
Tracked Since Feb 26, 2026