Critical severity9.8NVD Advisory· Published Mar 27, 2026· Updated Apr 2, 2026
CVE-2026-25101
CVE-2026-25101
Description
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session.
This issue was fixed in version 3.17.2.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.pl/posts/2026/03/CVE-2026-25099nvdThird Party Advisory
- github.com/bludit/bludit/releases/tag/3.17.2nvdRelease Notes
News mentions
0No linked articles in our index yet.