CVE-2026-78428
HIGH
8,0
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: high
Integrity: high
Availability: none
Description
AI Translation Available
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
384
Session Fixation
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Web Based, Web Server
https://bugzilla.suse.com/show_bug.cgi?id=1279937
https://github.com/neuvector/neuvector/security/advisories/GHSA-c6rx-pmvf-m3jx