{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/articatech/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-66745"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Artica Proxy"],"_cs_severities":["high"],"_cs_tags":["vulnerability","session-fixation","web-application","proxy"],"_cs_type":"advisory","_cs_vendors":["ArticaTech"],"content_html":"\u003cp\u003eCVE-2026-66745 is a critical session fixation vulnerability impacting Artica Proxy installations prior to version 4.50.000000 Service Pack 7, which was addressed in hotfix 20260724-02. This flaw enables unauthenticated attackers to gain full administrative access to an affected Artica Proxy instance without needing valid credentials. The attack involves the adversary setting a specific, known PHPSESSID cookie in a victim's browser before the victim authenticates. When the legitimate user subsequently logs into the Artica Proxy via the \u003ccode\u003efw.login.php\u003c/code\u003e page, the vulnerable application reuses the attacker-controlled session identifier instead of creating a new, unique one. This allows the attacker to use the pre-set PHPSESSID to access the administrative interface, typically on port 9000, as a fully authenticated user. The vulnerability's ease of exploitation and potential for complete system compromise make it a significant concern for organizations using Artica Proxy.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a vulnerable Artica Proxy instance exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker generates a specific, attacker-controlled PHPSESSID value.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious link or web page that, when visited by a target administrative user, sets the attacker-controlled PHPSESSID cookie for the Artica Proxy domain in the user's browser.\u003c/li\u003e\n\u003cli\u003eThe legitimate administrative user is lured to the Artica Proxy login page, \u003ccode\u003efw.login.php\u003c/code\u003e, with the pre-set PHPSESSID cookie already present.\u003c/li\u003e\n\u003cli\u003eThe administrative user provides their valid credentials and successfully authenticates to the Artica Proxy.\u003c/li\u003e\n\u003cli\u003eDue to the session fixation vulnerability, the Artica Proxy server reuses the existing, attacker-controlled PHPSESSID for the newly authenticated session instead of issuing a fresh one.\u003c/li\u003e\n\u003cli\u003eThe attacker then uses their browser, which still holds the pre-set PHPSESSID, to navigate directly to the Artica Proxy administrative interface, typically accessible on port 9000.\u003c/li\u003e\n\u003cli\u003eThe Artica Proxy validates the attacker's PHPSESSID, granting the attacker a fully authenticated administrative session and complete control over the proxy server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66745 grants an unauthenticated attacker full administrative privileges over the affected Artica Proxy instance. This allows for complete control over network traffic, including the ability to monitor, redirect, or block user activity, manipulate data, and potentially pivot to other systems within the internal network. The compromise of a proxy server can lead to significant data breaches, unauthorized access to internal resources, and disruption of critical network services, affecting all users whose traffic flows through the compromised proxy.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately apply the hotfix 20260724-02 or upgrade Artica Proxy to version 4.50.000000 Service Pack 7 or later to patch CVE-2026-66745. Refer to the vendor's release notes linked in the references for instructions.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests to \u003ccode\u003efw.login.php\u003c/code\u003e that include unusual or repeated PHPSESSID values from different client IPs, which could indicate attempts to exploit this vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement secure cookie attributes (e.g., \u003ccode\u003eHttpOnly\u003c/code\u003e, \u003ccode\u003eSecure\u003c/code\u003e, \u003ccode\u003eSameSite\u003c/code\u003e) and consider session regeneration upon authentication to mitigate session fixation attacks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T19:27:59Z","date_published":"2026-07-28T19:27:59Z","id":"https://feed.craftedsignal.io/briefs/2026-07-artica-proxy-session-fixation/","summary":"A session fixation vulnerability, CVE-2026-66745, in Artica Proxy before version 4.50.000000 Service Pack 7 allows unauthenticated attackers to hijack administrative sessions by pre-setting a PHPSESSID on a victim's browser, leading to full administrative control upon victim authentication.","title":"Artica Proxy Session Fixation Vulnerability CVE-2026-66745","url":"https://feed.craftedsignal.io/briefs/2026-07-artica-proxy-session-fixation/"}],"language":"en","title":"CraftedSignal Threat Feed - ArticaTech","version":"https://jsonfeed.org/version/1.1"}