CVE-2026-25101
Session Fixation in Bludit
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in version 3.17.2.
| CWE | CWE-384 |
| Vendor | bludit |
| Product | bludit |
| Published | Mar 27, 2026 |
| Last Updated | Mar 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for bludit bludit
Be the first to know when new unknown vulnerabilities affecting bludit bludit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Bludit / Bludit
0 < 3.17.2
References
Credits
Arkadiusz Marta