Session Fixation Vulnerability in Artica Proxy by Artica Tech
CVE-2026-66745

7.5HIGH

Key Information:

Vendor

Articatech

Vendor
CVE Published:
28 July 2026

What is CVE-2026-66745?

Artica Proxy prior to version 4.50.000000 Service Pack 7 is susceptible to a session fixation vulnerability. An attacker can exploit this flaw by pre-setting a known PHP session identifier on a victim's browser before the victim logs in. Once the victim authenticates through the login interface, the attacker gains unauthorized access to the victim's administrative session on port 9000, allowing potential manipulation of sensitive settings and data. It is crucial for users of affected versions to apply the recommended hotfix immediately to safeguard against these risks.

Affected Version(s)

Artica Proxy 0 <= 4.50.000000 Service Pack 6

Artica Proxy 0 <= 4.50.000000 Service Pack 6

Artica Proxy 4.50.000000

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TAH JOEL NEHEMIE
.