Impact
An issue in HubCore version 14.1.1's session cookie handling component allows an attacker able to set or modify the HUBCOREID cookie to elevate privileges beyond intended levels. By forging a valid session token, the attacker can authenticate as a privileged user and perform actions normally restricted to higher roles, thereby compromising system integrity and protecting data confidentiality.
Affected Systems
HubCore version 14.1.1 is the only affected product; other versions or vendors are not listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity, yet the EPSS score of <1% suggests a low likelihood of exploitation. The flaw is not listed in CISA KEV, indicating no known public exploitation. Despite the low exploit probability, an attacker who can tamper with session cookies can achieve full administrative access.
OpenCVE Enrichment