What is CVE-2026-66745?
This vulnerability is a session fixation issue in Artica Proxy versions before 4.50.000000 Service Pack 7. Unauthenticated attackers can hijack administrative sessions by setting a known PHPSESSID on the victim's browser prior to authentication. Updating to hotfix 20260724-02 is recommended.
Azərbaycanca: Bu boşluq Artica Proxy-nin 4.50.000000 Service Pack 7-dən əvvəlki versiyalarında aşkarlanmış session fixation zəifliyidir. Doğrulanmamış hücumçular qurbanın brauzerinə əvvəlcədən məlum PHPSESSID təyin edərək admin sessiyalarını ələ keçirə bilər. Cihazı hotfix 20260724-02 ilə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of Artica Proxy are affected by CVE-2026-66745?
Artica Proxy versions before 4.50.000000 Service Pack 7 are affected by this vulnerability.
How can an attacker hijack an admin session using CVE-2026-66745?
An unauthenticated attacker can perform session fixation by setting a known PHPSESSID on the victim's browser prior to authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.