Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access. | |
| Title | HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier | |
| Weaknesses | CWE-384 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T14:22:08.931Z
Reserved: 2026-09-17T13:55:53.598Z
Link: CVE-2026-92984
No data.
Status : Received
Published: 2026-09-17T15:17:01.690
Modified: 2026-09-17T15:17:01.690
Link: CVE-2026-92984
No data.
OpenCVE Enrichment
No data.