Description
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.
Published: 2026-09-17
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Session hijacking through session fixation, allowing account takeover
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows an attacker to supply a session identifier in the URL or request variables instead of cookies. A malicious user can obtain a valid session token, send a crafted link to a victim, and replay that token after the victim authenticates. This permits the attacker to hijack the victim’s session and gain access to their account, compromising confidentiality and integrity of the victim’s data.

Affected Systems

Hubzero CMS versions up to and including 2.2.32 are affected. The product is open‑source and distributed under the hubzero CMS name. Users running these specific releases should confirm their build version and apply any available updates.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, with no EPSS data available and the vulnerability not listed in the CISA KEV catalog. The likely attack vector is a manually crafted URL or link sent to a target user, a form of social engineering or phishing. An attacker who can distribute such a link and obtains a victim’s session ID before login can reuse the identifier to impersonate the victim after they authenticate.

Generated by OpenCVE AI on September 17, 2026 at 21:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Hubzero CMS update that removes the ability to accept session identifiers from query strings.
  • If no immediate update is available, alter the Session Manager code or configuration to reject session IDs passed via URL parameters or request variables, permitting session identifiers only from cookies.
  • Verify that session identifiers are regenerated after successful authentication and remove any legacy code or plugins that may still propagate session identifiers through GET or POST requests.

Generated by OpenCVE AI on September 17, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hubzero
Hubzero hubzero-cms
Vendors & Products Hubzero
Hubzero hubzero-cms

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.
Title HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier
Weaknesses CWE-384
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hubzero Hubzero-cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:43:24.447Z

Reserved: 2026-09-17T13:55:53.598Z

Link: CVE-2026-92984

cve-icon Vulnrichment

Updated: 2026-09-21T20:43:18.953Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:17:01.690

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:13Z

Weaknesses