Back Redpacketsecurity CVE Alert: CVE-2026-92984 – hubzero – hubzero
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.
High risk and worthy of urgent remediation, although exploitation status cannot be confirmed because KEV, SSVC, EPSS and PoC indicators were not provided.
A successful attack could let an unauthenticated outsider take over an authenticated user’s web session, exposing private content and enabling actions with that user’s authority. The most credible objectives are account takeover, theft of sensitive research or organisational data, and unauthorised changes made through privileged accounts; service availability is not the primary concern.
### Most likely attack path
The network-reachable, low-complexity, no-privilege path requires active victim interaction, such as following a maliciously prepared link. The attacker then reuses the resulting session context after authentication; scope remains within the application, but compromise of an administrator could materially extend impact across managed content and users.
### Who is most exposed
Internet-facing HUBzero portals, particularly academic, research, government and community deployments with self-registration, external users or administrator access through the same site, are the main concern. Sites using federated login or shared privileged accounts warrant additional scrutiny.
web and reverse-proxy logs for session identifiers supplied in query strings or non-cookie request fields.
Investigate unusual authenticated activity following link referrals, redirects or unfamiliar user agents.
Review concurrent sessions, abrupt location changes and privileged actions immediately after login.
Monitor account changes, content publication and data access associated with suspicious sessions.
### Mitigation and prioritisation
Apply the vendor patch promptly; treat this as a high-priority application security change.
Invalidate existing sessions after remediation and require reauthentication for privileged users.
Temporarily block or strip session identifiers in URLs at the proxy, after testing legitimate workflows.
Enforce secure cookie-only session handling and prohibit session reuse across authentication events.
If exploitation evidence, KEV status or EPSS ≥ 0.5 emerges, **treat as priority 1** and expedite emergency change procedures.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
