Executive brief
Pinpoint, an application performance management tool, fails to properly secure its login session tokens. This flaw allows attackers to potentially steal a user's session through malicious scripts or by intercepting unencrypted network traffic. If successful, an attacker could gain full access to the Pinpoint dashboard and its monitoring data, leading to unauthorized access to sensitive system performance information.
Technical details
An insecure session management vulnerability exists in Pinpoint's 'basicLogin' mode due to the 'pinpointJwt' cookie being issued without 'HttpOnly' and 'Secure' flags. The root cause is located in the 'BasicLoginService.createNewCookie()' method, which fails to set these security attributes. This allows the session token to be accessed by client-side JavaScript (enabling exfiltration via XSS) and transmitted in cleartext over HTTP (enabling interception via network sniffing). An attacker can leverage this to perform session hijacking and gain the privileges of the authenticated user. The vulnerability affects all versions up to and including 3.1.0.
Affected products
- pinpoint-apm Pinpoint <= 3.1.0
Timeline
- 2026-06-16: disclosed: Issue reported on GitHub repository
- 2026-06-29: advisory: CVE published to NVD