Executive brief
Artica Proxy, a web gateway and proxy appliance, is vulnerable to a session hijacking flaw. An attacker can trick an administrator into using a pre-set session ID; once the administrator logs in, the attacker gains full administrative control over the device. This could allow an unauthorized user to intercept network traffic, modify security policies, or access sensitive corporate data.
Technical details
A session fixation vulnerability exists in Artica Proxy's administrative interface (port 9000) within the fw.login.php component. The application fails to regenerate the session identifier (PHPSESSID) upon successful user authentication. An unauthenticated remote attacker can exploit this by pre-setting a specific session ID in a victim's browser (typically via social engineering or physical access). Once the victim authenticates using that session, the attacker can use the same ID to gain full administrative access. The vulnerability is addressed in version 4.50.000000 Service Pack 7 via hotfix 20260724-02.
Affected products
- ArticaTech Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02)
Timeline
- 2026-07-24: patched: Hotfix 20260724-02 released
- 2026-07-28: disclosed: CVE-2026-66745 published