CVE-2026-25101
EUVD-2026-1658127.03.2026, 12:16
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in version 3.17.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bludit | bludit | 𝑥 < 3.17.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration