PT-2026-94348 · Opencast · Opencast

·

CVE-2026-77614

·

Published

2026-07-16

·

Updated

2026-10-01

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Opencast versions prior to 19.7 Opencast versions prior to 20.2
Description The default security configuration in etc/security/mh default org.xml accepts a client-selected session identifier from the ;jsessionid= URL path parameter and fails to replace it upon user authentication. An unauthenticated attacker can provide a crafted link to a user without an active session cookie and, once the user authenticates, reuse that identifier to hijack the authenticated session. This can lead to unauthorized access to user data and actions, or full administrative account takeover if the victim has administrator privileges.
Recommendations Update to version 19.7 or later. Update to version 20.2 or later.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15028
CVE-2026-77614
GHSA-6F53-JP7X-GG7P

Affected Products

Opencast