Description
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. An attacker who can obtain an unauthenticated SysReptor session cookie, place it in a victim's browser, and know the shared-note URL where the victim authenticates can reuse the fixed session after the victim enters the correct password and access that shared note. The main SysReptor login flow is not affected. This issue is fixed in version 2026.68.
Published: 2026-09-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Session fixation on password‑protected shared notes
Action: Patch
AI Analysis

Impact

SysReptor, a customizable pentest reporting platform, does not rotate the session identifier after a user authenticates to a password‑protected shared note. This omission permits an attacker who has obtained an unauthenticated session cookie to force a victim to reuse that cookie after they enter the correct password, thereby gaining unauthorized access to the shared note. The flaw is limited to the shared‑note authentication flow; the main website login remains unaffected.

Affected Systems

System users running Syslifters SysReptor versions before 2026.68 are impacted. The vulnerability applies to any release prior to the 2026.68 update, regardless of other configuration settings.

Risk and Exploitability

The CVSS score is 3.7, indicating a low severity. The EPSS score is not available, so the likelihood of exploitation is currently unknown; however, once the vulnerability is known it could be abused if an attacker can capture an unauthenticated session cookie and know the shared‑note URL. The issue is not listed in CISA’s Known Exploited Vulnerabilities catalog. Based on the description, the most likely attack vector would involve an attacker delivering a crafted cookie to a victim and then directing the victim to access the shared note, after which the attacker can use the same session to read the content.

Generated by OpenCVE AI on September 19, 2026 at 12:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SysReptor to version 2026.68 or later, which rotates the session identifier on shared‑note authentication.
  • After upgrading, reset existing session identifiers for all users who had access to shared notes to invalidate any potentially fixed sessions.
  • Configure the web application to set session cookies with the Secure, HttpOnly, and SameSite attributes to reduce the risk of cookie theft or cross‑site request forgery.

Generated by OpenCVE AI on September 19, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. An attacker who can obtain an unauthenticated SysReptor session cookie, place it in a victim's browser, and know the shared-note URL where the victim authenticates can reuse the fixed session after the victim enters the correct password and access that shared note. The main SysReptor login flow is not affected. This issue is fixed in version 2026.68.
Title SysReptor: Session Fixation in Password-Protected Shared Notes
Weaknesses CWE-384
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:48:53.253Z

Reserved: 2026-08-26T16:26:08.967Z

Link: CVE-2026-81181

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-18T18:17:15.963

Modified: 2026-09-18T18:17:16.093

Link: CVE-2026-81181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:15:17Z

Weaknesses