CVE-2026-27933 - Vulnerability Analysis
MediumCVSS: 6.8Last Updated: February 27, 2026
Manyfold - Authentication Bypass
Published: February 26, 2026Updated: February 27, 2026PoC AvailableRemote Exploitable
Overview
Manyfold < 0.133.0 contains a session hijack vulnerability caused by cookie leakage in proxy caches, letting remote attackers hijack user sessions, exploit requires proxy cache presence.
Severity & Score
Severity: Medium
CVSS Score: 6.8
Impact
Attackers can hijack user sessions, leading to unauthorized access to user accounts and data.
Mitigation
Upgrade to version 0.133.0 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-27933
- Severity
- Medium
- CVSS Score
- 6.8
- Type
- broken_authentication
- Status
- confirmed
CWE
- CWE-613
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N