ZeroHour

CVE-2026-1758

moderate

Session Fixation in Secomea GateManager Web Interface Enables Account Takeover

CVSS 3.1
8.3 high
EPSS
Published
()
Modified
AI analysis

Secomea GateManager, the central server component of Secomea's remote-access platform for industrial (OT/ICS) equipment, contains a session fixation flaw (CWE-384) in its webserver module. An attacker can plant or predetermine a session identifier before the victim logs in — for example by tricking the victim into authenticating with an attacker-supplied link or token, consistent with the 'user interaction required' scoring — and then reuse that same session token after login to hijack the victim's authenticated web session. Successful exploitation gives the attacker the victim's access to the GateManager console, which typically manages remote connections to PLCs, CNCs, and other industrial devices, implying high confidentiality and integrity impact (CVSS 8.3). Affected deployments are GateManager 11.5 and 11.4.625515072; the issue is fixed in 11.6 and in 11.4.626194074 and above. No public proof of concept is known and the flaw is not listed in CISA's KEV, so exploitation appears to be theoretical at this time.

What to do: Upgrade GateManager to version 11.6 (or 11.4.626194074 or later if remaining on the 11.4 branch) as soon as practical. Until patched, restrict access to the GateManager web login page to trusted networks/VPN, avoid authenticating through links supplied by third parties, and log out idle sessions. After remediation, review GateManager audit logs for anomalous session reuse or unfamiliar concurrent logins on privileged accounts.

Affected
Secomea GateManager (webserver module)
Estimated exposure
moderatelikely low thousands of GateManager instances worldwide (estimated) — GateManager is deployed roughly one per customer organization or site (on-premises appliance or Secomea-hosted cloud), and public internet scanning services typically show only low thousands of exposed Secomea GateManager web interfaces,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.