Junglewise Threat Intelligence

CVE-2026-33384: OpenSolution QuickCMS session fixation

CVE-2026-33384 · Severity: info · CVSS 0 · Published 2026-05-29

Technologies: OpenSolution Quick.CMS. Vendors: OpenSolution.

Executive brief

QuickCMS is a content management system used to build and manage websites. A security flaw allows an attacker to pre-set a user's session ID, which remains active even after the user logs in. This allows the attacker to hijack the user's authenticated session, potentially gaining full access to their account and administrative controls.

Technical details

QuickCMS is vulnerable to a session fixation attack (CWE-384). The application fails to regenerate the session identifier upon a successful login, allowing a session ID established prior to authentication to persist. An attacker can provide a known session ID to a victim (e.g., via URL parameters or cookie injection) and then hijack the session once the victim authenticates. This issue affects all versions up to 6.8 and was addressed in a specific security patch released on May 15, 2026.

Affected products

  • OpenSolution QuickCMS Up to 6.8 (prior to 2026-05-15 patch)

Timeline

  • 2026-05-15: patched: Patch for version 6.8 released
  • 2026-05-29: advisory: Public disclosure by CERT Polska

References

Related threats