CVE-2026-77614
Last modified
CVE-2026-77614 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jsessionid= URL path parameter and does not replace it when the victim logs in.
Description
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jsessionid= URL path parameter and does not replace it when the victim logs in. An unauthenticated attacker can send a crafted link to a victim whose browser has no active Opencast session cookie, wait for the victim to authenticate, and then reuse the known identifier as the victim's authenticated session. This can expose the victim's data and actions and can produce full administrative account takeover when the victim is an administrator. This issue is fixed in versions 19.7 and 20.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| opencast | opencast | < 19.7; >= 20.0, < 20.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-77614?
How severe is CVE-2026-77614?
How do I fix CVE-2026-77614?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77607Semantic MediaWiki is a free, open-source extension to Media…6.1
- CVE-2026-77608Semantic MediaWiki is a free, open-source extension to Media…6.1
- CVE-2026-77609Semantic MediaWiki is a free, open-source extension to Media…6.1
- CVE-2026-7761The Ultimate Member plugin for WordPress is vulnerable to Ac…8.8
- CVE-2026-77610Semantic MediaWiki is a free, open-source extension to Media…6.1
- CVE-2026-77611SeaweedFS is a distributed storage system for files and blob…7.1
- CVE-2026-77615Paella Player is a set of libraries to create a multi stream…8.7
- CVE-2026-77616Semantic MediaWiki is a free, open-source extension to Media…6.1
- CVE-2026-77619Vector is a high-performance observability data pipeline. Fr…8.7
- CVE-2026-7762A heap-based buffer overflow vulnerability in the dot11ah.ko…9.8
- CVE-2026-77620Vector is a high-performance observability data pipeline. Fr…8.7
- CVE-2026-77621Vector is a high-performance observability data pipeline. Fr…9.3
Are you affected by CVE-2026-77614?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
