Session Fixation Vulnerability in HUBzero CMS by HUBzero
CVE-2026-92984
8.5HIGH
What is CVE-2026-92984?
HUBzero CMS versions up to 2.2.32 expose a critical security flaw by accepting session identifiers via query strings and request variables, rather than restricting them to cookies. This design flaw enables unauthenticated attackers to carry out session fixation attacks. By obtaining a valid session identifier and crafting a malicious link, attackers can trick victims into clicking it. Once the victim authenticates, the attacker can replay the session identifier, hijacking the victim's account and potentially gaining unauthorized access to sensitive information. Comprehensive remediation is essential to protect user accounts and ensure the integrity of the system.
Affected Version(s)
hubzero-cms 0 <= 2.2.32
