Description
The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.
Published: 2026-09-29
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Session Takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because the application accepts session identifiers supplied by the user and fails to regenerate a new session ID after authentication. This behavior allows an attacker to predefine a session ID, have a victim authenticate, and then reuse that same ID. The result is a thorough session takeover, enabling an attacker to assume the victim’s identity and access protected resources with the victim’s privileges.

Affected Systems

The flaw affects Toptech Systems’ TMS7 and TopHAT products. No specific affected versions are cited beyond the mention that the issue is resolved in release 7.8, implying that all earlier releases could be vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, yet the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation in the wild. The probable attack path requires the attacker to deliver a crafted request containing a chosen session identifier before the victim logs in, usually via the web interface or API. Defenses rely on server‑side session regeneration and input validation to prevent session fixation.

Generated by OpenCVE AI on September 30, 2026 at 10:20 UTC.

Remediation

Vendor Solution

Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security


OpenCVE Recommended Actions

  • Upgrade to Toptech Systems release 7.8 or later, which includes session ID regeneration after authentication.
  • Verify that the application forbids the use of client‑supplied session identifiers by enforcing server‑generated session IDs and rejecting any session ID attached to requests after authentication.
  • Harden the session handling logic by validating session IDs against a secure, random token generation process and applying CSRF protection to prevent session fixation attacks.

Generated by OpenCVE AI on September 30, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.
Title Toptech TMS7 and TopHAT Session Fixation
Weaknesses CWE-384
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-30T15:28:14.550Z

Reserved: 2026-08-10T17:31:09.961Z

Link: CVE-2026-71302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T22:18:18.817

Modified: 2026-09-30T16:46:43.953

Link: CVE-2026-71302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T10:30:17Z

Weaknesses