# CVE-2026-2177

## Summary

- **CVE ID:** CVE-2026-2177
- **Severity:** MEDIUM
- **CVSS Score:** 7.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-384
- **Published:** Feb 8, 2026
- **Last Modified:** Mar 12, 2026

## Description

A vulnerability has been found in SourceCodester Prison Management System 1.0. The impacted element is an unknown function of the component Login. The manipulation leads to session fixiation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

## Affected Products

- SourceCodester — Prison Management System (1.0)

## References

- [CNA](https://vuldb.com/?id.344880)
- [CNA](https://vuldb.com/?ctiid.344880)
- [CNA](https://vuldb.com/?submit.749485)
- [CNA](https://github.com/hater-us/CVE/issues/10)
- [CNA](https://www.sourcecodester.com/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._