Description
Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session identifier and wait for a victim to authenticate through fw.login.php, after which the attacker gains a fully authenticated administrative session on port 9000.
Published: 2026-07-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Artica Proxy before version 4.50.000000 Service Pack 7 allows an unauthenticated attacker to set a known PHPSESSID value in a victim’s browser. When the victim subsequently authenticates through fw.login.php on port 9000, the attacker gains a fully authenticated administrative session. The vulnerability arises from insufficient protection against session fixation, enabling remote privilege escalation. This flaw allows the attacker to become a fully authenticated administrator after the victim logs in, without executing arbitrary code.

Affected Systems

Vulnerable systems are Artica Proxy deployments running any build of 4.50.000000 before Service Pack 7. The issue impacts the default administrative web interface on port 9000 and, by extension, any service that utilizes this inter‑session mechanism. Users of ArticaTech’s Proxy product should review the build number and service pack in use.

Risk and Exploitability

The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the flaw is not listed in the CISA KEV catalog, indicating no known active exploitation. Nevertheless, a successful exploit would grant full administrative access, enabling arbitrary configuration changes or further lateral movement. The attack requires the ability to pre‑set a PHPSESSID cookie before the victim logs in, a capability that can be achieved remotely via crafted URLs or cross‑site request forgery.

Generated by OpenCVE AI on August 3, 2026 at 14:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official hotfix 20260724-02 (Artica Proxy 4.50.000000 Service Pack 7) released by ArticaTech
  • Upgrade to the latest Artica Proxy release (4.50.000000 Service Pack 7 or newer) to ensure the session‑fixation fix is in place
  • Configure the web server or application to reject externally supplied PHPSESSID values (e.g., via URL or form) as a temporary countermeasure while awaiting an official update

Generated by OpenCVE AI on August 3, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:articatech:artica_proxy:*:*:*:*:*:*:*:*
cpe:2.3:a:articatech:artica_proxy:4.50.000000:*:*:*:*:*:*:*

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Articatech
Articatech artica Proxy
Vendors & Products Articatech
Articatech artica Proxy

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session identifier and wait for a victim to authenticate through fw.login.php, after which the attacker gains a fully authenticated administrative session on port 9000.
Title Artica Proxy 4.50 Session Fixation via fw.login.php
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Articatech Artica Proxy
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T16:50:44.621Z

Reserved: 2026-07-27T16:27:47.647Z

Link: CVE-2026-66745

cve-icon Vulnrichment

Updated: 2026-07-29T13:59:55.065Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T19:17:41.440

Modified: 2026-07-30T20:11:09.180

Link: CVE-2026-66745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')