Session Cookie Vulnerability in Boruta Authorization Server by Malach IT
CVE-2026-53661
8.8HIGH
What is CVE-2026-53661?
The Boruta authorization server is vulnerable due to session cookies being set without the Secure attribute, potentially exposing them over unencrypted HTTP. Attackers observing network traffic can intercept valid session or remember-me cookies, enabling user impersonation. This issue affects Boruta Web, Boruta Identity, and Boruta Admin components. Patching is essential as it sets appropriate attributes on the cookies to enhance security. Until an upgrade to version 0.9.1, it's critical to enforce HTTPS-only access, apply HSTS, and rotate sensitive keys if exposure is suspected.
Affected Version(s)
boruta-server < 0.9.1
