SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-9507

UNKNOWN · CVSS N/A EPSS 0.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-16 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. See the original NVD description below for full technical details.

CVE
CVE-2026-9507
Severity
UNKNOWN
CVSS
N/A
EPSS
0.40%

Original NVD Description

A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijack a victim’s account by keeping the initial session identifier (OSTSESSID) active after a successful login. The issue lies in the fact that the application does not invalidate the pre-authentication cookie or generate a new identifier for the authenticated context. As a result, if an attacker manages to set a known session identifier in the victim’s browser, they will be able to maintain unauthorised access to the account once the victim has authenticated.