๐Ÿ” CVE Alert

CVE-2026-77614

HIGH 8.8

Opencast: Session fixation in login enables account takeover via crafted link

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jsessionid= URL path parameter and does not replace it when the victim logs in. An unauthenticated attacker can send a crafted link to a victim whose browser has no active Opencast session cookie, wait for the victim to authenticate, and then reuse the known identifier as the victim's authenticated session. This can expose the victim's data and actions and can produce full administrative account takeover when the victim is an administrator. This issue is fixed in versions 19.7 and 20.2.

CWE CWE-384
Vendor opencast
Product opencast
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for opencast opencast

Be the first to know when new high vulnerabilities affecting opencast opencast are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

opencast / opencast
< 19.7 >= 20.0, < 20.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/opencast/opencast/security/advisories/GHSA-6f53-jp7x-gg7p github.com: https://github.com/opencast/opencast/commit/c36652250a026afb7cf78b663950c702669f1d3f github.com: https://github.com/opencast/opencast/commit/ff84128c9b3bcbd79c28192d25929dab8faf185f github.com: https://github.com/opencast/opencast/releases/tag/19.7 github.com: https://github.com/opencast/opencast/releases/tag/20.2