Threadlinqs IntelligenceStart free

Weakness · CompoundCWE-384

CWE-384: Session Fixation

Compound

As of 2026-10-05, CWE-384 (Session Fixation) underlies 3 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 18 tracked threats.

CVEs
3Mapped to CWE-384
CISA KEV
0None listed yet
Critical
0CVSS v3 critical CVEs
Threats
18Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-384?

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Such a scenario is commonly observed when: A web application authenticates a user without first invalidating the existing session, thereby continuing to use the session already associated with the user. An attacker is able to force a known session identifier on a user so that, once the user authenticates, the attacker has access to the authenticated session. The application or container uses predictable session identifiers. In the generic exploit of session fixation vulnerabilities, an attacker creates a new session on a web application and records the associated session identifier. The attacker then causes the victim to associate, and possibly authenticate, against the server using that session identifier, giving the attacker access to the user's account through the active session.

CWE-384 is a compound-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: Web Server.

Source: MITRE CWE (CWE-384 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Gain Privileges or Assume Identity

Source: MITRE CWE, common consequences.

How CWE-384 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-384, published between 2026-06-25 and 2026-09-22. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 3 medium. The highest EPSS score in the set is 0.4% (CVE-2026-95828), the modelled probability of exploitation in the next 30 days. 18 tracked threats reference CWE-384 directly or through a CVE it covers; the most recent is “CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD” (2026-10-02). Affected products concentrate in Cacti (1), Mstfakts (1), TryGhost (1).

Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-384, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

18 tracked threats cite CWE-384:

Mitigations

  • Architecture and Design: Invalidate any existing session identifiers prior to authorizing a new user session.
  • Architecture and Design: For platforms such as ASP that do not generate new values for sessionid cookies, utilize a secondary cookie. In this approach, set a secondary cookie on the user's browser to a random value and set a session variable to the same value. If the session variable and the cookie value ever don't match, invalidate the session, and force the user to log on again.
  • Operation / Firewall: Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].

Source: MITRE CWE, potential mitigations.