CVE-2026-57948
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-1004, CWE-614
- Published
- 2026-06-29
- Last modified
- 2026-07-14
Affected products
- pinpoint-apm pinpoint
Weakness type
Related vulnerabilities
- CVE-2026-82697 — sambitraj Student-Management-System session_start cookie httponly flag
- CVE-2026-21754 — HCL Hive is affected by multiple security vulnerabilities.
- CVE-2026-11956 — TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
- CVE-2026-42239 — Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
- CVE-2026-39338 — ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration
- CVE-2026-35575 — ChurchCRM has Stored XSS in Group Name
- CVE-2026-25736 — Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
- CVE-2026-25735 — Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name