CWE-384: Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
179 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-38513 — Fiber Session Middleware Token Injection Vulnerability
- CVE-2025-59841 — FlagForgeCTF's Improper Session Handling Allows Access After Logout
- CVE-2025-52689 — Weak Session ID Check in the OmniAccess Stellar Web Management Interface
- CVE-2024-13967 — ession-Management Failure
- CVE-2026-22082 — Insecure Session ID Management Vulnerability in Tenda Wireless Routers
- CVE-2026-24894 — FrankenPHP leaks session data between requests in worker mode
- CVE-2025-0126 — PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login
- CVE-2026-18527 — IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
- CVE-2026-33946 — MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
- CVE-2025-53102 — Discourse's WebAuthn challenge isn't cleared from user session after authentication
- CVE-2025-42602 — Improper Authentication Vulnerability in Meon KYC solutions
- CVE-2026-33757 — OpenBao lacks user confirmation for OIDC direct callback mode
- CVE-2025-46815 — ZITADEL Allows IdP Intent Token Reuse
- CVE-2025-29928 — authentik's deletion of sessions did not revoke sessions when using database session storage
- CVE-2024-22250 — Session Hijack Vulnerability in Deprecated EAP Browser Plugin
- CVE-2026-56425 — MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection
- CVE-2025-53895 — ZITADEL has broken authN and authZ in session API and resulting session tokens
- CVE-2026-81826 — Flowintel Fails to Invalidate Active Sessions After Password Change
- CVE-2009-10007 — Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks
- CVE-2026-2177 — SourceCodester Prison Management System Login session fixiation
Recently published
- CVE-2026-64857 — tirreno has Session Fixation in Login Authentication
- CVE-2026-86674 — ningzichun Student Management System login.php session_start session fixiation
- CVE-2026-76196 — Photoshop Mobile | Session Fixation (CWE-384)
- CVE-2026-86279 — SourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_process.php session fixiation
- CVE-2026-85238 — Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking
- CVE-2026-18527 — IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
- CVE-2026-81826 — Flowintel Fails to Invalidate Active Sessions After Password Change
- CVE-2026-70594 — Ghost: Session Fixation in Ghost Admin
- CVE-2026-69245 — Guzzle: Noncanonical cookie domain keeps subdomain scope
- CVE-2026-16496 — terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
- CVE-2026-59883 — Guzzle: Cookie Disclosure and Injection via IP-Address Domains
- CVE-2026-14609 — SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation
- CVE-2026-13707 — Session fixation attacks on improperly configured OAuth 1.0a tools
- CVE-2026-56224 — Capgo - Login CSRF and Session Fixation via URL Query Parameters
- CVE-2026-35095 — Session fixation in KTM System e-BOK
- CVE-2026-40082 — Cacti: Session Fixation via missing session_regenerate_id() after login
- CVE-2026-56425 — MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection
- CVE-2026-12581 — Digiwin|EasyFlow .NET - Session Fixation
- CVE-2009-10007 — Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks
- CVE-2026-41839 — Spring Framework Escalation via Session Fixation in WebFlux