Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-384 (会话固定) — Vulnerability Class 184

184 vulnerabilities classified as CWE-384 (会话固定). AI Chinese analysis included.

CWE-384, Session Fixation, is an authentication weakness where an application fails to invalidate existing session identifiers upon user login. This flaw allows attackers to predict or fix a victim’s session ID before authentication occurs. Typically, an attacker tricks a user into accessing a malicious link containing the attacker’s known session ID. When the victim logs in, the server associates the authenticated session with that pre-existing ID, granting the attacker immediate access to the victim’s account without needing credentials. To prevent this, developers must generate a new, random session identifier immediately after successful authentication. Additionally, implementing secure session management practices, such as regenerating IDs after privilege changes and using secure, HTTP-only cookies, ensures that stolen session tokens remain useless to attackers, effectively mitigating the risk of session hijacking.

MITRE CWE Description
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions. Such a scenario is commonly observed when: A web application authenticates a user without first invalidating the existing session, thereby continuing to use the session already associated with the user. An attacker is able to force a known session identifier on a user so that, once the user authenticates, the attacker has access to the authenticated session. The application or container uses predictable session identifiers. In the generic exploit of session fixation vulnerabilities, an attacker creates a new session on a web application and records the associated session identifier. The attacker then causes the victim to associate, and possibly authenticate, against the server using that session identifier, giving the attacker access to the user's account through the active session.
Common Consequences (1)
Access Control Gain Privileges or Assume Identity
Mitigations (3)
Architecture and Design Invalidate any existing session identifiers prior to authorizing a new user session.
Architecture and Design For platforms such as ASP that do not generate new values for sessionid cookies, utilize a secondary cookie. In this approach, set a secondary cookie on the user's browser to a random value and set a session variable to the same value. If the session variable and the cookie value ever don't match, invalidate the session, and force the user to log on again.
Operation Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].
Effectiveness: Moderate
Examples (2)
The following example shows a snippet of code from a J2EE web application where the application authenticates users with LoginContext.login() without first calling HttpSession.invalidate().
private void auth(LoginContext lc, HttpSession session) throws LoginException { ... lc.login(); ... }
Bad · Java
The following example shows a snippet of code from a J2EE web application where the application authenticates users with a direct post to the <code>j_security_check</code>, which typically does not invalidate the existing session before processing the login request.
<form method="POST" action="j_security_check"> <input type="text" name="j_username"> <input type="text" name="j_password"> </form>
Bad · HTML
CVE ID Title CVSS Severity Published
CVE-2026-107229 AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing onto public-suffix and IP-address hosts — async-http-client 4.0 Medium 2026-10-07
CVE-2026-92414 Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens — Apache Jackrabbit 9.3 Critical 2026-10-07
CVE-2026-105233 kishor-23 food-waste-management-system Login Flow login.php session fixiation — food-waste-management-system 6.3 Medium 2026-10-05
CVE-2026-104469 YesWiki before 4.6.7 Session Fixation via Login in AuthController.php — yeswiki 6.8 Medium 2026-10-02
CVE-2026-71302 Toptech TMS7 and TopHAT Session Fixation — TMS7 7.1 High 2026-09-29
CVE-2026-92609 Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication — Apache Qpid Broker-J - - 2026-09-25
CVE-2026-57179 social-auth-core has a Session Fixation issue — social-core 4.2 Medium 2026-09-24
CVE-2026-95828 Mstfakts College-Management-System Authentication server.php session_start session fixiation — College-Management-System 4.3 Medium 2026-09-22
CVE-2026-82355 Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation — Apache Airflow - - 2026-09-21
CVE-2026-81181 SysReptor: Session Fixation in Password-Protected Shared Notes — sysreptor 3.7 Low 2026-09-18
CVE-2026-86688 Session id is not renewed on authentication in ash_authentication, allowing session fixation — ash_authentication 7.4 High 2026-09-17
CVE-2026-77614 Opencast: Session fixation in login enables account takeover via crafted link — opencast 8.8 High 2026-09-17
CVE-2026-92984 HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier — hubzero-cms 8.1 High 2026-09-17
CVE-2026-61592 djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack) — djust 7.4 High 2026-09-16
CVE-2026-69214 Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain — http4s 6.8 Medium 2026-09-15
CVE-2026-1758 Session Fixation — GateManager 8.3 High 2026-09-15
CVE-2026-64857 tirreno has Session Fixation in Login Authentication — tirreno 5.3 Medium 2026-09-09
CVE-2026-86674 ningzichun Student Management System login.php session_start session fixiation — Student Management System 6.3 Medium 2026-09-08
CVE-2026-76196 Photoshop Mobile | Session Fixation (CWE-384) — Photoshop Android 7.4 High 2026-09-08
CVE-2026-86279 SourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_process.php session fixiation — Syllabus-Aligned Learning Management & Examination System 6.3 Medium 2026-09-07
CVE-2026-85238 Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking — misp 7.6 High 2026-09-03
CVE-2026-18527 IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ]. — Administration Runtime Expert for i 9.9 Critical 2026-08-28
CVE-2026-70594 Ghost: Session Fixation in Ghost Admin — Ghost 6.7 Medium 2026-08-04
CVE-2026-16496 terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user — Tooling 8.9 High 2026-07-28
CVE-2026-14609 SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation — CET Automated Grading System with AI Predictive Analytics 5.6 Medium 2026-07-03
CVE-2026-13707 Session fixation attacks on improperly configured OAuth 1.0a tools — OAuth - - 2026-07-01
CVE-2026-56224 Capgo - Login CSRF and Session Fixation via URL Query Parameters — Capgo 5.4 Medium 2026-06-30
CVE-2026-35095 Session fixation in KTM System e-BOK — e-BOK - - 2026-06-30
CVE-2026-40082 Cacti: Session Fixation via missing session_regenerate_id() after login — cacti 5.4 Medium 2026-06-25
CVE-2026-56425 MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection — misp - - 2026-06-22

Vulnerabilities classified as CWE-384 (会话固定) represent 184 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.