Description
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jsessionid= URL path parameter and does not replace it when the victim logs in. An unauthenticated attacker can send a crafted link to a victim whose browser has no active Opencast session cookie, wait for the victim to authenticate, and then reuse the known identifier as the victim's authenticated session. This can expose the victim's data and actions and can produce full administrative account takeover when the victim is an administrator. This issue is fixed in versions 19.7 and 20.2.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via session fixation
Action: Immediate Patch
AI Analysis

Impact

Opencast’s default security configuration allows a client‑selected JSESSIONID to be passed through the ;jsessionid URL path parameter. When a victim’s browser has no existing Opencast session cookie and subsequently authenticates, the supplied identifier persists as an authenticated session. This flaw permits the attacker to hijack the victim’s authenticated session, exposing the victim’s data and, if the victim holds administrative privileges, enabling a full administrative account takeover. The weakness is characterized by CWE‑384, Session Fixation.

Affected Systems

All Opencast platform releases prior to 19.7 and prior to 20.2 are vulnerable because the mh_default_org.xml security configuration accepts client‑provided JSESSIONID values. Versions 19.7 and 20.2 contain the necessary fix to prevent session fixation. Any installations running earlier versions are therefore exposed to the described risk.

Risk and Exploitability

The CVSS base score of 8.8 reflects a high‑severity vulnerability. The EPSS score is not available, so the exact network exploitation probability remains unclear (this lack of data is inferred). Because the flaw can be exploited simply by sending a crafted link to any victim with a fresh browser session, attackers do not need elevated privileges. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of an already‑known campaign targeting it. Nonetheless, the ability to hijack authentication sessions keeps the risk significant for any exposed deployment.

Generated by OpenCVE AI on September 17, 2026 at 20:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Opencast updates to at least version 19.7 or 20.2, which fix the session fixation flaw.
  • If an immediate upgrade is not possible, edit the mh_default_org.xml configuration file to disallow client‑provided JSESSIONID values, ensuring the server generates session identifiers.
  • As a temporary defense, instruct users to avoid clicking suspicious links and configure the server to disable URL‑based session identifiers when possible.

Generated by OpenCVE AI on September 17, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Opencast
Opencast opencast
Vendors & Products Opencast
Opencast opencast

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jsessionid= URL path parameter and does not replace it when the victim logs in. An unauthenticated attacker can send a crafted link to a victim whose browser has no active Opencast session cookie, wait for the victim to authenticate, and then reuse the known identifier as the victim's authenticated session. This can expose the victim's data and actions and can produce full administrative account takeover when the victim is an administrator. This issue is fixed in versions 19.7 and 20.2.
Title Opencast: Session fixation in login enables account takeover via crafted link
Weaknesses CWE-384
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Opencast Opencast
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:33:11.344Z

Reserved: 2026-08-20T20:52:01.926Z

Link: CVE-2026-77614

cve-icon Vulnrichment

Updated: 2026-09-17T15:33:07.287Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:16:51.503

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-77614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses