← back
CVE-2026-25101

Session Fixation in Bludit

CVSS 4.8 MEDIUMEPSS 0.4%CWE-384
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
27 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in version 3.17.2.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Bludit · Bludit

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →