Session Token Vulnerability in Hydro Online Judge Platform
CVE-2026-55617
6.9MEDIUM
What is CVE-2026-55617?
The Hydro Online Judge Platform presents a session token vulnerability affecting versions 4.10.4 through 5.0.2. This issue arises from the server's failure to delete old session tokens during the recreation process. As a result, stale session cookies can remain valid even after a user has logged out or refreshed their session. An attacker with access to a valid stale cookie can exploit this flaw to perform actions on behalf of the victim without requiring their credentials or interaction. Such a vulnerability risks unauthorized access to sensitive information and privileged actions on the user's account. The issue was addressed in version 5.0.2.
Affected Version(s)
Hydro >= 4.10.4, < 5.0.2
