Session Management Flaw in Opencast Affects User Authentication
CVE-2026-77614

8.8HIGH

Key Information:

Vendor

Opencast

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-77614?

Opencast is an open-source platform supporting the management of educational audio and video content. Prior to versions 19.7 and 20.2, a significant vulnerability existed in the default security settings. The platform's configuration allowed the acceptance of a client-selected JSESSIONID from the URL path parameter, without ensuring it was replaced during user authentication. This flaw enabled unauthenticated attackers to exploit the system by sending crafted links to users without active session cookies. When the victim authenticated, the attacker could hijack the session by reusing the known identifier, potentially leading to unauthorized access and full administrative account takeover. This vulnerability has been addressed in the recent versions of Opencast.

Affected Version(s)

opencast < 19.7 < 19.7

opencast >= 20.0, < 20.2 < 20.0, 20.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.