Session Management Flaw in Opencast Affects User Authentication
CVE-2026-77614
What is CVE-2026-77614?
Opencast is an open-source platform supporting the management of educational audio and video content. Prior to versions 19.7 and 20.2, a significant vulnerability existed in the default security settings. The platform's configuration allowed the acceptance of a client-selected JSESSIONID from the URL path parameter, without ensuring it was replaced during user authentication. This flaw enabled unauthenticated attackers to exploit the system by sending crafted links to users without active session cookies. When the victim authenticated, the attacker could hijack the session by reusing the known identifier, potentially leading to unauthorized access and full administrative account takeover. This vulnerability has been addressed in the recent versions of Opencast.
Affected Version(s)
opencast < 19.7 < 19.7
opencast >= 20.0, < 20.2 < 20.0, 20.2
