LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-14948

Published
CVSS8.8
Severityhigh
WeaknessCWE-532
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-14948

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-14948.