PULSE
FEED
ransomqilin reclama a Thai Lion Air · TH · Transportationransomrhysida reclama a Mat Bao Corporation · VN · Technologyransompanzer reclama a Paessolucoes · BR · Otherransomrhysida reclama a Electro Heat Sweden AB · SE · Energy & Utilitiesransomqilin reclama a Sports Events365 · GB · Hospitalityransomauditteam reclama a Ad***ng · AE · Technologyransomakira reclama a The Official College of Architects of León (COAL) · MX · Professional Servicesransomakira reclama a Jampac Alimentos · BR · Agriculture and Food Productionransomakira reclama a Pacific Tank Lines · US · Transportationransomqilin reclama a Inova Semiconductors GmbH · DE · Manufacturingransombooba project reclama a Raleigh Family Medicine · US · Healthcareransombooba project reclama a EdgeEndo® USA · US · Healthcareransombooba project reclama a Soni Medical Centre · CA · Healthcareransombooba project reclama a University of Illinois Chicago · US · Educationransomqilin reclama a Thai Lion Air · TH · Transportationransomrhysida reclama a Mat Bao Corporation · VN · Technologyransompanzer reclama a Paessolucoes · BR · Otherransomrhysida reclama a Electro Heat Sweden AB · SE · Energy & Utilitiesransomqilin reclama a Sports Events365 · GB · Hospitalityransomauditteam reclama a Ad***ng · AE · Technologyransomakira reclama a The Official College of Architects of León (COAL) · MX · Professional Servicesransomakira reclama a Jampac Alimentos · BR · Agriculture and Food Productionransomakira reclama a Pacific Tank Lines · US · Transportationransomqilin reclama a Inova Semiconductors GmbH · DE · Manufacturingransombooba project reclama a Raleigh Family Medicine · US · Healthcareransombooba project reclama a EdgeEndo® USA · US · Healthcareransombooba project reclama a Soni Medical Centre · CA · Healthcareransombooba project reclama a University of Illinois Chicago · US · Education
← All CVEs
CVE WatchSep 29, 2026

CVE-2026-101268

If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the

CVSS

—

No CVSS

EPSS

0.2%

p8

KEV

—

Exploit Today

3

0-100

Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-384

EPSS · 30d
0.2%EPSS · 30 days0.2%
2026-09-302026-10-02
Technical description

If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1044696.8 MED
—
——0YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.17h
CVE-2026-1024899.8 CRI
45.8%
KEV—64Zammad GmbH Zammad Session Fixation Vulnerability11h
CVE-2026-713027.1 HIG
19.2%
——6The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.3d
CVE-2026-926099.8 CRI
29.5%
——9Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.8d
CVE-2026-571794.2 MED
4.3%
——1Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session.8d
CVE-2026-958284.3 MED
39.7%
——12A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead to session fixiation. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.10d