Session Cookie Vulnerability in Boruta Authorization Server by Malach IT
CVE-2026-53661

8.8HIGH

Key Information:

Vendor

Malach-it

Vendor
CVE Published:
11 June 2026

What is CVE-2026-53661?

The Boruta authorization server is vulnerable due to session cookies being set without the Secure attribute, potentially exposing them over unencrypted HTTP. Attackers observing network traffic can intercept valid session or remember-me cookies, enabling user impersonation. This issue affects Boruta Web, Boruta Identity, and Boruta Admin components. Patching is essential as it sets appropriate attributes on the cookies to enhance security. Until an upgrade to version 0.9.1, it's critical to enforce HTTPS-only access, apply HSTS, and rotate sensitive keys if exposure is suspected.

Affected Version(s)

boruta-server < 0.9.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.