High severity7.1NVD Advisory· Published Sep 29, 2026
Toptech TMS7 and TopHAT
CVE-2026-71302
Description
The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.
Affected products
2Patches
Vulnerability mechanics
News mentions
1- Toptech TMS7 and TopHATCISA ICS Advisories