Description
Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation.

This issue affects GateManager: 11.5;0, 11.4.625515072:0.



Fixed in Version 11.6 or 11.4.626194074 and above
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Session Hijacking via Session Fixation
Action: Apply Patch
AI Analysis

Impact

A session fixation flaw in the webserver module of Secomea GateManager lets an attacker set a valid session identifier before user authentication. By forcing the application to accept a chosen session ID, the attacker can later impersonate the legitimate user, gaining unauthorized access to protected resources. The weakness is a classic example of CWE‑384, which can compromise confidentiality and integrity of user data. The impact extends to any user interacting with the affected GateManager instance, potentially allowing full administrative takeover if the session is granted elevated privileges.

Affected Systems

The vulnerability affects Secomea GateManager webserver module. Affected releases include GateManager 11.5.0 and GateManager 11.4.625515072.0. Versions 11.6 and 11.4.626194074 or any later release contain the patch and are not vulnerable.

Risk and Exploitability

The CVSS score of 8.3 classifies this flaw as high risk. The EPSS score is 0.00241, indicating a very low probability of exploitation, but the vulnerability is listed in external advisories and is not yet included in CISA’s KEV catalog. Based on the description, it is inferred that the flaw can be exploited through the web interface, where an attacker can craft a request to assign a session ID via URL or cookie. Successful exploitation requires the attacker to reach the application’s authentication flow; it does not need remote code execution or privileged access before the attack.

Generated by OpenCVE AI on September 17, 2026 at 18:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GateManager to version 11.6 or 11.4.626194074 or newer, which resolves the session fixation issue.
  • After upgrading, review the GateManager session configuration to ensure that session identifiers are generated server‑side and cannot be set via user input or URL parameters.
  • Implement monitoring of authentication requests for attempts to set session IDs prior to login, and reject any such attempts to prevent potential fixation attacks.

Generated by OpenCVE AI on September 17, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Secomea
Secomea gatemanager
Vendors & Products Secomea
Secomea gatemanager

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above
Title Session Fixation
Weaknesses CWE-384
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'}


Subscriptions

Secomea Gatemanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Secomea

Published:

Updated: 2026-09-15T12:23:59.107Z

Reserved: 2026-02-02T12:07:47.997Z

Link: CVE-2026-1758

cve-icon Vulnrichment

Updated: 2026-09-15T12:23:51.351Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T11:17:07.587

Modified: 2026-09-18T19:30:42.730

Link: CVE-2026-1758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses