Session Hijacking Vulnerability in Bludit by Bludit
CVE-2026-25101

4.8MEDIUM

Key Information:

Vendor

Bludit

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-25101?

Bludit contains a security flaw that permits an attacker to fix a user's session identifier prior to authentication. This session ID remains unchanged even after the user successfully logs in, creating an opportunity for the attacker to seize control of the authenticated session later. It is crucial for users to update to version 3.17.2 or later to safeguard against this vulnerability.

Affected Version(s)

Bludit 0 < 3.17.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arkadiusz Marta
.