CVE-2026-92984

Source
https://cve.org/CVERecord?id=CVE-2026-92984
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92984.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92984
Published
2026-09-17T14:22:08Z
Modified
2026-09-19T03:47:31Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier
Details

HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-384"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92984.json"
}
References

Affected packages

Git / github.com/hubzero/hubzero-cms

Affected ranges

Type
GIT
Repo
https://github.com/hubzero/hubzero-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.2.32"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.1.0-release
v0.*
v0.7.0
v0.8.0
v0.8.0-20100405.1
v0.8.0-20100405.2
v0.8.0-20100406.1
v0.8.0-20100406.2
v0.8.0-20100407.1
v0.8.0-20100408.1
v0.8.0-20100408.2
v0.8.0-20100408.3
v0.8.0-20100408.4
v0.8.0-20100408.5
v0.8.0-20100408.6
v1.*
v1.0.0
v1.0.0-20110326.1
v1.0.0-20110327.1
v1.0.0-20110327.2
v1.0.0-20110328.1
v1.0.0-20110402.1
v1.0.0-20110402.2
v1.0.0-20110403.1
v1.0.0-20110403.2
v1.0.0-20110403.3
v1.1.0
v1.1.0-20120823
v1.1.0-20120827
v1.1.0-20120923.6
v1.1.2
v1.2.0
v1.2.1
v1.2.2
v1.3.0.24
v2.*
v2.0.0.0
v2.0.0.1
v2.0.0.2
v2.0.0.3
v2.0.0.4
v2.1.0
v2.2.0
v2.2.1
v2.2.10
v2.2.11
v2.2.12
v2.2.13
v2.2.14
v2.2.15
v2.2.16
v2.2.17
v2.2.18
v2.2.19
v2.2.2
v2.2.20
v2.2.21
v2.2.22
v2.2.23
v2.2.24
v2.2.25
v2.2.27
v2.2.28
v2.2.3
v2.2.30
v2.2.31
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92984.json"