PT-2026-96773 · Debian+1 · Web.Py

CVE-2026-79312

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions web.py version 0.76
Description Session Fixation occurs because the Session. load() function reads the session id directly from the request cookie and loads that session from the store. Subsequently, the save() function writes back using the same session id. Since there is no session rotation after authentication, a fixed session id maintains the authenticated state.
Recommendations Update web.py to a version where session rotation is implemented after authentication. As a temporary mitigation, restrict the use of the Session. load() and save() functions to ensure session identifiers are rotated upon login.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79312

Affected Products

Web.Py