What is CWE-384?
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Such a scenario is commonly observed when: A web application authenticates a user without first invalidating the existing session, thereby continuing to use the session already associated with the user. An attacker is able to force a known session identifier on a user so that, once the user authenticates, the attacker has access to the authenticated session. The application or container uses predictable session identifiers. In the generic exploit of session fixation vulnerabilities, an attacker creates a new session on a web application and records the associated session identifier. The attacker then causes the victim to associate, and possibly authenticate, against the server using that session identifier, giving the attacker access to the user's account through the active session.
CWE-384 is a compound-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: Web Server.
Source: MITRE CWE (CWE-384 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Gain Privileges or Assume Identity
Source: MITRE CWE, common consequences.
How CWE-384 is exploited in the wild
Threadlinqs maps 3 CVEs to CWE-384, published between 2026-06-25 and 2026-09-22. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 3 medium. The highest EPSS score in the set is 0.4% (CVE-2026-95828), the modelled probability of exploitation in the next 30 days. 18 tracked threats reference CWE-384 directly or through a CVE it covers; the most recent is “CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD” (2026-10-02). Affected products concentrate in Cacti (1), Mstfakts (1), TryGhost (1).
Vulnerabilities (CVEs)
All 3 CVEs mapped to CWE-384, CISA KEV first, then by CVSS score.
- CVE-2026-70594 — CVSS 6.7 medium · EPSS 0.1% · published 2026-08-04
- CVE-2026-40082 — CVSS 5.4 medium · published 2026-06-25
- CVE-2026-95828 — CVSS 4.3 medium · EPSS 0.4% · published 2026-09-22
Affected vendors
Threat activity
18 tracked threats cite CWE-384:
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVDCRITICAL
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)HIGH
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and DjangoCRITICAL
- CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine AD360 ProductsCRITICAL
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data ExfiltrationCRITICAL
- Cloud vn105rkj64 — Italian Invoice Phishing Drops Windows Backdoor and Force-Installed Chrome Extension Abusing Native Messaging for Cookie Theft, MFA Bypass, and Remote PowerShellHIGH
- Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service MarketplacesHIGH
- Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public SectorHIGH
- BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account TakeoverHIGH
- Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised)CRITICAL
- CVE-2026-40372: ASP.NET Core Data Protection Authentication Cookie Forgery Enables Unauthenticated SYSTEM Privilege EscalationCRITICAL
- CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session HijackCRITICAL
- W3LL Phishing-as-a-Service Ecosystem Dismantled — FBI/Indonesia Takedown of $20M BEC PlatformHIGH
- Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS SessionsHIGH
- EvilTokens PhaaS Campaign Abuses Railway.com PaaS for Microsoft 365 Device Code Phishing and AiTM Token ReplayCRITICAL
- Tycoon2FA Phishing-as-a-Service Platform Persists Post-Europol Takedown with Rapid Infrastructure RecoveryCRITICAL
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA BypassHIGH
- ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential TheftHIGH
Mitigations
- Architecture and Design: Invalidate any existing session identifiers prior to authorizing a new user session.
- Architecture and Design: For platforms such as ASP that do not generate new values for sessionid cookies, utilize a secondary cookie. In this approach, set a secondary cookie on the user's browser to a random value and set a session variable to the same value. If the session variable and the cookie value ever don't match, invalidate the session, and force the user to log on again.
- Operation / Firewall: Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].
Source: MITRE CWE, potential mitigations.