Junglewise Threat Intelligence

CVE-2026-14609: SourceCodester CET Automated Grading System session fixation

CVE-2026-14609 · Severity: medium · CVSS 5.6 · Published 2026-07-03

Technologies: SourceCodester CET Automated Grading System with AI Predictive Analytics. Vendors: SourceCodester.

Executive brief

A session fixation vulnerability exists in the SourceCodester CET Automated Grading System, a platform used for academic grading and predictive analytics. This flaw could allow a remote attacker to hijack a user's session, potentially gaining unauthorized access to student grades or administrative functions. While the attack is complex to execute, it poses a risk to the integrity and confidentiality of academic data.

Technical details

A session fixation vulnerability (CWE-384) exists in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The vulnerability occurs during session processing, where the application fails to properly invalidate or renew session identifiers. A remote attacker can exploit this by forcing a known session ID on a victim; if the victim authenticates using that ID, the attacker can then use the fixed session to impersonate the user. The attack is classified as having high complexity and is considered difficult to exploit, though proof-of-concept details are reportedly public.

Affected products

  • SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

Timeline

  • 2026-07-03: disclosed: Initial disclosure via VulDB and NVD

References

Related threats