CIVI-SA-2026-02: Standalone - Session Fixation

Publicat
2026-03-18 12:00
Written by

If two users share access to the same client device, then a Session Fixation vulnerability enables the first user to impersonate the second user.

Security Risk
Critical
Vulnerability
Other
Affected Versions

CiviCRM v6.12.0 and earlier (Standalone only)

Fixed Versions

CiviCRM v6.12.1, v6.10.3 (ESR), and later (Standalone only)

Publication Date
Solutions

Upgrade to a fixed version of CiviCRM

Credits

Tim Otten (CiviCRM), Rich Lott (Artful Robot), Benjamin W