PT-2026-96773 · Debian+1 · Web.Py
CVE-2026-79312
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
web.py version 0.76
Description
Session Fixation occurs because the
Session. load() function reads the session id directly from the request cookie and loads that session from the store. Subsequently, the save() function writes back using the same session id. Since there is no session rotation after authentication, a fixed session id maintains the authenticated state.Recommendations
Update web.py to a version where session rotation is implemented after authentication.
As a temporary mitigation, restrict the use of the
Session. load() and save() functions to ensure session identifiers are rotated upon login.Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web.Py