CVE-2026-14948
Severity CVSS v4.0:
HIGH
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
20/08/2026
Last modified:
20/08/2026
Description
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH


