CWE-565: Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
32 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-0257 — PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
- CVE-2025-2395 — e-Excellence U-Office Force - Improper Authentication
- CVE-2014-125112 — Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution
- CVE-2024-9970 — NewType FlowMaster BPM Plus - Privilege Escalation
- CVE-2024-22186 — Electrolink FM/DAB/TV Transmitter Reliance on Cookies without Validation and Integrity Checking
- CVE-2025-14440 — JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
- CVE-2024-0947 — Cookies Manipulation in Talya Informatics' Elektraweb
- CVE-2024-28233 — XSS in JupyterHub via Self-XSS leveraged by Cookie Tossing
- CVE-2026-85181 — CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
- CVE-2026-39324 — Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
- CVE-2026-5130 — Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation
- CVE-2026-53871 — Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie
- CVE-2025-64447 — A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1,
- CVE-2026-75757 — AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain
- CVE-2026-39963 — Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain
- CVE-2025-31120 — NamelessMC Vulnerable to Cookie-Based View Count Manipulation
- CVE-2026-8337 — Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
Recently published
- CVE-2026-85181 — CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
- CVE-2026-75757 — AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain
- CVE-2026-53871 — Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie
- CVE-2026-8337 — Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
- CVE-2026-0257 — PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
- CVE-2026-39963 — Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain
- CVE-2026-39324 — Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
- CVE-2026-5130 — Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation
- CVE-2014-125112 — Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution
- CVE-2025-14440 — JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
- CVE-2025-64447 — A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1,
- CVE-2025-31120 — NamelessMC Vulnerable to Cookie-Based View Count Manipulation
- CVE-2025-2395 — e-Excellence U-Office Force - Improper Authentication
- CVE-2024-9970 — NewType FlowMaster BPM Plus - Privilege Escalation
- CVE-2024-0947 — Cookies Manipulation in Talya Informatics' Elektraweb
- CVE-2024-22186 — Electrolink FM/DAB/TV Transmitter Reliance on Cookies without Validation and Integrity Checking
- CVE-2024-28233 — XSS in JupyterHub via Self-XSS leveraged by Cookie Tossing
More specific weaknesses
- CWE-784 — Reliance on Cookies without Validation and Integrity Checking in a Security Decision