Junglewise Threat Intelligence

CVE-2026-75171: HubCore session fixation via HUBCOREID cookie

CVE-2026-75171 · Severity: critical · CVSS 9.8 · Published 2026-09-04

Executive brief

HubCore is a Destination Management System (DMS) used by tour operators and travel agencies to manage bookings, inventory, and tourism product distribution. A vulnerability in the HUBCOREID session cookie handling allows unauthenticated remote attackers to escalate their privileges, potentially enabling unauthorized access to customer data, bookings, and business operations across the platform.

Technical details

The vulnerability is a session fixation issue in HubCore v14.1.1 affecting the HUBCOREID session cookie handling component. The flaw allows a remote attacker to perform privilege escalation without requiring prior authentication, indicating the cookie validation or session management logic can be bypassed or manipulated. Attack preconditions are minimal—network access to the HubCore platform is required. An attacker can exploit this to assume elevated privileges and potentially access sensitive tourism booking data, customer information, and administrative functions. No patch information is currently available.

Affected products

  • HubCore HubCore 14.1.1

Timeline

  • 2026-09-04: disclosed

References