SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14948

HIGH · CVSS 8.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability allows low-privileged remote attackers to hijack active administrative sessions by extracting plaintext session identifiers from downloadable error log archives, bypassing the need for administrator passwords. This poses a significant risk to systems where sensitive administrative actions can be performed, potentially leading to unauthorized access and control. Organizations with administrative interfaces exposed to the internet should prioritize addressing this vulnerability to mitigate the risk of session hijacking.

CVE
CVE-2026-14948
Severity
HIGH
CVSS
8.8
EPSS
0.40%

Original NVD Description

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.