CVE-2026-75171
—Unauthenticated Privilege Escalation via Session Fixation in HubCore 14.1.1
HubCore v14.1.1 contains a session handling flaw (CWE-384) in the component that manages the HUBCOREID session cookie, allowing a remote attacker to escalate privileges. Because the flaw is in session cookie handling, an unauthenticated network attacker can likely fixate or assume a victim's HUBCOREID session identifier — for example, by planting or reusing a cookie value that the server does not regenerate at authentication or privilege transitions — and thereby impersonate a higher-privileged (potentially administrative) account. The CVSS 3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U with high confidentiality, integrity, and availability impact) reflects a remotely exploitable, unauthenticated flaw with severe consequences for any deployment running the affected version. Only HubCore v14.1.1 is named in the CVE data, so other versions' status is unconfirmed. Exploitation status is quiet: no public PoC, no CISA KEV entry, and a low EPSS score of 0.2% (13th percentile) indicate no known in-the-wild attacks to date.
What to do: Patch to a HubCore release that fixes HUBCOREID session handling as soon as the vendor ships one; if no fixed version exists, contact the vendor for a hotfix. In the interim, mitigate by ensuring the application issues a fresh, random HUBCOREID session cookie at login and on any privilege change, invalidates sessions on logout, and restricts access to HubCore management interfaces (allow-listing/VPN) while monitoring logs for session IDs that persist across authentication or are reused from unusual source addresses.
| HubCore | 14.1.1 (only version explicitly named; fix status and other versions unknown from the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.
- Weakness
- CWE-384
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.