PT-2026-94357 · Unknown · Hubzero-Cms

·

CVE-2026-92984

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HUBzero CMS versions prior to 2.2.33
Description The software accepts session identifiers from query strings and request variables instead of relying exclusively on cookies. This allows unauthenticated attackers to perform session fixation, where they obtain a valid session identifier and trick a victim into using it via a crafted link. Once the victim authenticates, the attacker can replay the identifier to hijack the account and gain unauthorized access.
Recommendations Update HUBzero CMS to version 2.2.33 or later.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92984

Affected Products

Hubzero-Cms