Session Fixation Vulnerability in SysReptor Pentest Reporting Platform
CVE-2026-81181
3.7LOW
What is CVE-2026-81181?
The session fixation vulnerability in SysReptor prior to version 2026.68 arises from a flaw in the password authentication process for protected shared notes. This flaw allows an attacker to exploit an unauthenticated SysReptor session cookie by placing it in a victim's browser. If the attacker knows the URL for a shared note and the victim subsequently logs in correctly, the attacker can reuse the unaltered session cookie to access the shared note. Importantly, the primary SysReptor login flow remains unaffected. Users are encouraged to update to version 2026.68 to mitigate this risk.
Affected Version(s)
sysreptor < 2026.68
