CWE-384
L’identifiant de session n’est pas renouvelé à la connexion : l’attaquant réutilise celui qu’il a fixé.
- 3
- vulnérabilités suivies
- 1
- critiques
- 28 juillet 2026
- dernière publication
cve
Veille des vulnérabilités
identifiantvulnérabilitésévéritépublié
CVE-2026-16496The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0. Élevée CVSS 8.9 CVE-2021-32088An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.Quest Kace Systems Management Appliance Critique CVSS 9.8 CVE-2026-13707Session fixation vulnerability in Wikimedia Foundation OAuth.
This vulnerability is associated with program files src/Backend/MWOAuthServer.Php.
This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.Mediawiki Élevée CVSS 7.6