A low privileged remote attacker can hijack an active...
High severity
Unreviewed
Published
Aug 20, 2026
to the GitHub Advisory Database
•
Updated Aug 20, 2026
Description
Published by the National Vulnerability Database
Aug 20, 2026
Published to the GitHub Advisory Database
Aug 20, 2026
Last updated
Aug 20, 2026
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
References