Session Hijacking Vulnerability in JetBrains Datalore
CVE-2026-32745

6.3MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
13 March 2026

What is CVE-2026-32745?

JetBrains Datalore versions before 2026.1 are susceptible to session hijacking due to inadequate cookie security settings. The vulnerability arises from the absence of the secure attribute in cookie configurations, potentially allowing attackers to intercept session cookies. This could enable unauthorized access to user accounts and sensitive information. Users are urged to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Datalore 0 < 2026.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.