CVE-2026-1758
moderateSession Fixation in Secomea GateManager Web Interface Enables Account Takeover
Secomea GateManager, the central server component of Secomea's remote-access platform for industrial (OT/ICS) equipment, contains a session fixation flaw (CWE-384) in its webserver module. An attacker can plant or predetermine a session identifier before the victim logs in — for example by tricking the victim into authenticating with an attacker-supplied link or token, consistent with the 'user interaction required' scoring — and then reuse that same session token after login to hijack the victim's authenticated web session. Successful exploitation gives the attacker the victim's access to the GateManager console, which typically manages remote connections to PLCs, CNCs, and other industrial devices, implying high confidentiality and integrity impact (CVSS 8.3). Affected deployments are GateManager 11.5 and 11.4.625515072; the issue is fixed in 11.6 and in 11.4.626194074 and above. No public proof of concept is known and the flaw is not listed in CISA's KEV, so exploitation appears to be theoretical at this time.
What to do: Upgrade GateManager to version 11.6 (or 11.4.626194074 or later if remaining on the 11.4 branch) as soon as practical. Until patched, restrict access to the GateManager web login page to trusted networks/VPN, avoid authenticating through links supplied by third parties, and log out idle sessions. After remediation, review GateManager audit logs for anomalous session reuse or unfamiliar concurrent logins on privileged accounts.
| Secomea GateManager (webserver module) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above
- Weakness
- CWE-384
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.