Junglewise Threat Intelligence

CVE-2026-77614: Opencast session fixation via URL-based JSESSIONID

CVE-2026-77614 · Severity: high · CVSS 8.8 · Published 2026-09-17

Executive brief

Opencast is an open-source platform used by educational institutions to manage and distribute audio and video content. Prior to versions 19.7 and 20.2, the platform's default security configuration accepts session identifiers provided by attackers in URLs, allowing them to hijack authenticated sessions. An attacker can trick a user into clicking a malicious link, wait for them to log in, and then impersonate that user—potentially gaining full administrative access if the victim is an administrator.

Technical details

This is a session fixation vulnerability in Opencast's default security configuration (etc/security/mh_default_org.xml). The root cause is that Spring Security parses the jsessionid parameter from the URL when no session cookie is already present, and the application does not invalidate or replace this attacker-supplied identifier upon authentication. An unauthenticated attacker can craft a URL with a known jsessionid value, send it to a victim with no active session, and once the victim authenticates, the attacker can reuse that same identifier to access the authenticated session. The attack requires no authentication and no special network position; it relies only on social engineering (tricking the victim into clicking the link). The fix, applied in versions 19.7 and 20.2, sets disable-url-rewriting="true" in the Spring Security configuration to prevent URL-based session ID parsing.

Affected products

  • Opencast Opencast before 19.7 and before 20.2

Timeline

  • 2026-09-17: disclosed: Vulnerability published on NVD
  • 2026-09-17: patched: Fixed in versions 19.7 and 20.2

References

Related threats