CVE 7.6 HIGH

Pinpoint – Insecure Session Cookie Attributes in pinpointJwt_CVE-2026-57948

7.6 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.

Basic Information

ID CVE-2026-57948
Source VulnCheck
Published Jun 29, 2026 at 17:19

Affected Product

Vendor pinpoint-apm
Product pinpoint
Affected Versions pinpoint-apm pinpoint 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.