๐Ÿ” CVE Alert

CVE-2026-66745

HIGH 7.5

Artica Proxy 4.50 Session Fixation via fw.login.php

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session identifier and wait for a victim to authenticate through fw.login.php, after which the attacker gains a fully authenticated administrative session on port 9000.

CWE CWE-94
Vendor articatech
Product artica proxy
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for articatech artica proxy

Be the first to know when new high vulnerabilities affecting articatech artica proxy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

ArticaTech / Artica Proxy
0 โ‰ค 4.50.000000 Service Pack 6 4.50.000000

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wiki.articatech.com: https://wiki.articatech.com/maintenance/upgrade-artica/hotfix-450000000 articatech.com: https://www.articatech.com/hotfixes.php?main=4.50.000000&sp=7 vulncheck.com: https://www.vulncheck.com/advisories/artica-proxy-session-fixation-via-fw-login-php

Credits

TAH JOEL NEHEMIE