Session Fixation Vulnerability in SysReptor Pentest Reporting Platform
CVE-2026-81181

3.7LOW

Key Information:

Vendor

Syslifters

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-81181?

The session fixation vulnerability in SysReptor prior to version 2026.68 arises from a flaw in the password authentication process for protected shared notes. This flaw allows an attacker to exploit an unauthenticated SysReptor session cookie by placing it in a victim's browser. If the attacker knows the URL for a shared note and the victim subsequently logs in correctly, the attacker can reuse the unaltered session cookie to access the shared note. Importantly, the primary SysReptor login flow remains unaffected. Users are encouraged to update to version 2026.68 to mitigate this risk.

Affected Version(s)

sysreptor < 2026.68

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.