# CWE-384: Session Fixation

> As of 2026-10-05, CWE-384 (Session Fixation) underlies 3 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 18 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-384?

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Such a scenario is commonly observed when: A web application authenticates a user without first invalidating the existing session, thereby continuing to use the session already associated with the user. An attacker is able to force a known session identifier on a user so that, once the user authenticates, the attacker has access to the authenticated session. The application or container uses predictable session identifiers. In the generic exploit of session fixation vulnerabilities, an attacker creates a new session on a web application and records the associated session identifier. The attacker then causes the victim to associate, and possibly authenticate, against the server using that session identifier, giving the attacker access to the user's account through the active session.

CWE-384 is a compound-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: Web Server.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/384.html) (CWE-384 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Gain Privileges or Assume Identity

_Source: MITRE CWE, common consequences._

## How CWE-384 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-384, published between 2026-06-25 and 2026-09-22. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 3 medium. The highest EPSS score in the set is 0.4% (CVE-2026-95828), the modelled probability of exploitation in the next 30 days. 18 tracked threats reference CWE-384 directly or through a CVE it covers; the most recent is “CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD” (2026-10-02). Affected products concentrate in Cacti (1), Mstfakts (1), TryGhost (1).

## Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-384, CISA KEV first, then by CVSS score.

- [CVE-2026-70594](https://intel.threadlinqs.com/cve/CVE-2026-70594) — CVSS 6.7 medium · EPSS 0.1% · published 2026-08-04
- [CVE-2026-40082](https://intel.threadlinqs.com/cve/CVE-2026-40082) — CVSS 5.4 medium · published 2026-06-25
- [CVE-2026-95828](https://intel.threadlinqs.com/cve/CVE-2026-95828) — CVSS 4.3 medium · EPSS 0.4% · published 2026-09-22

## Affected vendors

- [Cacti](https://intel.threadlinqs.com/vendors/cacti) — 1 CVE
- **Mstfakts** — 1 CVE
- [TryGhost](https://intel.threadlinqs.com/vendors/tryghost) — 1 CVE

## Threat activity

18 tracked threats cite CWE-384:

- [CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD](https://intel.threadlinqs.com/threat/TL-2026-2843) — CRITICAL · 2026-10-02
- [Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)](https://intel.threadlinqs.com/threat/TL-2026-2757) — HIGH · 2026-09-28
- [August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django](https://intel.threadlinqs.com/threat/TL-2026-1891) — CRITICAL · 2026-08-05
- [CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine AD360 Products](https://intel.threadlinqs.com/threat/TL-2026-1627) — CRITICAL · 2026-07-22
- [Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0976) — CRITICAL · 2026-06-28
- [Cloud vn105rkj64 — Italian Invoice Phishing Drops Windows Backdoor and Force-Installed Chrome Extension Abusing Native Messaging for Cookie Theft, MFA Bypass, and Remote PowerShell](https://intel.threadlinqs.com/threat/TL-2026-0948) — HIGH · 2026-06-26
- [Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service Marketplaces](https://intel.threadlinqs.com/threat/TL-2026-0919) — HIGH · 2026-06-23
- [Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public Sector](https://intel.threadlinqs.com/threat/TL-2026-0878) — HIGH · 2026-06-19
- [BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-0828) — HIGH · 2026-06-16
- [Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised)](https://intel.threadlinqs.com/threat/TL-2026-0449) — CRITICAL · 2026-05-02
- [CVE-2026-40372: ASP.NET Core Data Protection Authentication Cookie Forgery Enables Unauthenticated SYSTEM Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-0408) — CRITICAL · 2026-04-22
- [CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session Hijack](https://intel.threadlinqs.com/threat/TL-2026-0384) — CRITICAL · 2026-04-17
- [W3LL Phishing-as-a-Service Ecosystem Dismantled — FBI/Indonesia Takedown of $20M BEC Platform](https://intel.threadlinqs.com/threat/TL-2026-0373) — HIGH · 2026-04-16
- [Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS Sessions](https://intel.threadlinqs.com/threat/TL-2026-0355) — HIGH · 2026-04-13
- [EvilTokens PhaaS Campaign Abuses Railway.com PaaS for Microsoft 365 Device Code Phishing and AiTM Token Replay](https://intel.threadlinqs.com/threat/TL-2026-0278) — CRITICAL · 2026-03-24
- [Tycoon2FA Phishing-as-a-Service Platform Persists Post-Europol Takedown with Rapid Infrastructure Recovery](https://intel.threadlinqs.com/threat/TL-2026-0257) — CRITICAL · 2026-03-20
- [ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-0054) — HIGH · 2026-02-03
- [ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0030) — HIGH · 2026-02-02

## Mitigations

- **Architecture and Design**: Invalidate any existing session identifiers prior to authorizing a new user session.
- **Architecture and Design**: For platforms such as ASP that do not generate new values for sessionid cookies, utilize a secondary cookie. In this approach, set a secondary cookie on the user's browser to a random value and set a session variable to the same value. If the session variable and the cookie value ever don't match, invalidate the session, and force the user to log on again.
- **Operation / Firewall**: Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].

_Source: MITRE CWE, potential mitigations._

## Related weaknesses

- [CWE-610](https://cwe.mitre.org/data/definitions/610.html)
- [CWE-346 Origin Validation Error](https://intel.threadlinqs.com/cwe/CWE-346)
- [CWE-472](https://cwe.mitre.org/data/definitions/472.html)
- [CWE-441 Confused Deputy](https://intel.threadlinqs.com/cwe/CWE-441)

Canonical: https://intel.threadlinqs.com/cwe/CWE-384
Source definition: https://cwe.mitre.org/data/definitions/384.html
Detection rules and IOCs for threats exploiting CWE-384 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
