7.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Description
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.
Basic Information
ID
CVE-2026-57948
Source
VulnCheck
Published
Jun 29, 2026 at 17:19
Affected Product
Vendor
pinpoint-apm
Product
pinpoint
Affected Versions
pinpoint-apm pinpoint 0