CVE-2026-2439
Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using Perl's built-in rand function. Neither of these methods are secure, and attackers are able to guess session_ids that can grant them access to systems. Specifically, * There is no warning when uuidgen fails. The software can be quietly using the fallback rand() function with no warnings if the command fails for any reason. * The uuidgen command will generate a time-based UUID if the system does not have a high-quality random number source, because the call does not explicitly specify the --random option. Note that the system time is shared in HTTP responses. * UUIDs are identifiers whose mere possession grants access, as per RFC 9562. * The output of the built-in rand() function is predictable and unsuitable for security applications.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.42%
- CWE
- CWE-340, CWE-338
- Published
- 2026-02-16
- Last modified
- 2026-09-17
Affected products
- BVA Concierge::Sessions
Weakness type
Related vulnerabilities
- CVE-2025-69286 — RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability
- CVE-2024-7558 — JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K
- CVE-2025-68701 — Jervis has Deterministic AES IV Derivation from Passphrase
- CVE-2025-62294 — Predictable Generation of Password Recovery Token
- CVE-2026-3256 — HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids
- CVE-2025-15604 — Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions
- CVE-2025-40926 — Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely
- CVE-2026-75106 — OpnForm Editable Submission Secret Derivation via Empty Hashids Salt