Session Fixation Vulnerability in HUBzero CMS by HUBzero
CVE-2026-92984

8.5HIGH

Key Information:

Vendor

Hubzero

Vendor
CVE Published:
17 September 2026

What is CVE-2026-92984?

HUBzero CMS versions up to 2.2.32 expose a critical security flaw by accepting session identifiers via query strings and request variables, rather than restricting them to cookies. This design flaw enables unauthenticated attackers to carry out session fixation attacks. By obtaining a valid session identifier and crafting a malicious link, attackers can trick victims into clicking it. Once the victim authenticates, the attacker can replay the session identifier, hijacking the victim's account and potentially gaining unauthorized access to sensitive information. Comprehensive remediation is essential to protect user accounts and ensure the integrity of the system.

Affected Version(s)

hubzero-cms 0 <= 2.2.32

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.