Skip to content
Threat Feed

Tag

Session-Management

6 briefs RSS
high advisory

CSRF Vulnerability in Komari Management Interface

The Komari management interface lacks CSRF protections and secure cookie attributes, allowing an attacker to perform unauthorized administrative actions including arbitrary code execution.

komari web-application-security csrf session-management
1r 2t
high advisory

Memos Refresh Token Revocation Failure

Memos versions 0.26.0 through 0.30.0 fail to invalidate refresh tokens after a password change, enabling persistent unauthorized access via the RefreshToken RPC.

Memos session-management vulnerability mssql-bypass
1t 1c
critical advisory

WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding

WWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.

AVideo +7 credential-access web-application authentication-bypass web-application-vulnerability path-traversal reconnaissance web-vulnerability csrf +13
7r 15t 1c updated
high threat

CVE-2026-14996: IBM Aspera Faspex 5 Session Management Vulnerability

CVE-2026-14996 details a high-severity vulnerability (CVSS v3.1 8.2, CWE-613) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 that allows unauthenticated, remote attackers to exploit insufficient session management, leading to high confidentiality impact and low integrity impact.

exploited Aspera Faspex 5 +1 vulnerability session-management IBM cve
1t 1c
medium advisory

Question2Answer Session Invalidation Vulnerability

Attackers can exploit CVE-2026-64829, a session invalidation vulnerability in Question2Answer through version 1.8.8, where the forgot-password reset flow fails to clear the sessioncode field, allowing an attacker with a previously obtained remember-me cookie to retain authenticated access even after the account's password has been reset.

Question2Answer <= 1.8.8 question2answer vulnerability session-management web-application cve
2t 1c
high advisory

Open WebUI CORS Misconfiguration and Session Validation Vulnerability Leads to RCE

Open WebUI version v0.3.10 has a CORS misconfiguration and session validation issue that can lead to remote code execution due to a one-click attack against admin users.

open-webui cors rce session-management
2r 1t