{"id":"CVE-2026-92984","summary":"HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier","details":"HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.","modified":"2026-09-19T03:47:31.161027385Z","published":"2026-09-17T14:22:08.931Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-384"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92984.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92984.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92984"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/hubzero-cms-through-2.2.32-session-fixation-via-query-string-session-identifier"},{"type":"FIX","url":"https://github.com/hubzero/hubzero-cms/commit/e60e8ebee5e1d38b1db1fc41bd9164b265b24356"},{"type":"PACKAGE","url":"https://github.com/hubzero/hubzero-cms"},{"type":"ARTICLE","url":"https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/libraries/Hubzero/Session/Manager.php#L123-L132"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hubzero/hubzero-cms","events":[{"introduced":"0"},{"fixed":"c9cceaa29442cc63c9068304f18dfb029cec174b"},{"fixed":"e60e8ebee5e1d38b1db1fc41bd9164b265b24356"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"2.2.32"}]}}],"versions":["v2.4.5","v2.4.4","v2.4.3","v2.4.2","v2.4.1","v2.4.0","v2.2.31","v2.2.24","v2.2.30","v2.2.27","v2.2.28","v2.2.20","v2.2.25","v2.2.23","v2.2.22","v2.2.21","v2.2.19","v2.2.18","v2.2.17","v2.2.16","v2.2.15","v2.2.14","v2.2.13","v2.2.12","v2.2.11","v2.2.10","v2.2.9","v2.2.8","v2.2.7","v2.2.6","v2.2.5","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.1.0","2.1.0-release","v2.0.0.4","v2.0.0.3","v2.0.0.2","v2.0.0.1","v2.0.0.0","v1.3.0.24","v1.2.0","v1.2.2","v1.2.1","v1.1.2","v1.1.0-20120923.6","v1.1.0","v1.1.0-20120827","v1.1.0-20120823","v1.0.0-20110403.3","v1.0.0","v1.0.0-20110403.2","v1.0.0-20110403.1","v1.0.0-20110402.2","v1.0.0-20110402.1","v1.0.0-20110328.1","v1.0.0-20110327.2","v1.0.0-20110327.1","v1.0.0-20110326.1","v0.8.0-20100408.6","v0.8.0-20100408.2","v0.8.0","v0.8.0-20100408.5","v0.8.0-20100408.4","v0.8.0-20100408.3","v0.8.0-20100408.1","v0.8.0-20100407.1","v0.8.0-20100406.2","v0.8.0-20100406.1","v0.8.0-20100405.2","v0.8.0-20100405.1","v0.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92984.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}