Session Fixation in mod_auth_openidc - #VU142421
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to hijack a victim\'s authenticated session.
The vulnerability exists due to improper session management in login session handling when processing authentication for a browser presenting an attacker-fixed session identifier. A remote attacker can set a chosen session cookie and wait for the victim to authenticate to hijack a victim\'s authenticated session.
The attacker must be able to set a cookie for the host before the victim logs in.