CVE-2026-71302
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Sep 29, 2026
Vendor
unknown
Description
The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.