Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/3672641 |
Configurations
No configuration.
History
23 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 17:16
Updated : 2026-06-23 18:17
NVD link : CVE-2026-34917
Mitre link : CVE-2026-34917
CVE.ORG link : CVE-2026-34917
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
