CVE-2026-81181 Details
Description
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. An attacker who can obtain an unauthenticated SysReptor session cookie, place it in a victim's browser, and know the shared-note URL where the victim authenticates can reuse the fixed session after the victim enters the correct password and access that shared note. The main SysReptor login flow is not affected. This issue is fixed in version 2026.68.
A session fixation vulnerability has been identified in SysReptor, a customizable pentest reporting platform, prior to version 2026.68. The issue arises in the password authentication flow for protected shared notes, where the session identifier is not rotated after successful authentication. This flaw allows an attacker to hijack a user's session by placing a fixed session cookie in their browser, provided they know the URL of the shared note being accessed. The vulnerability does not impact the main login process.
Users can update to SysReptor version 2026.68 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Syslifters/sysreptor/commit/1981717f15afe945aa86d7e0dc9dc30a30c88dea | [email protected] | Source CodeVendor |
| https://github.com/Syslifters/sysreptor/releases/tag/2026.68 | [email protected] | Release NotesVendor |
| https://github.com/Syslifters/sysreptor/security/advisories/GHSA-wgx3-84xg-q93j | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-384 | Session Fixation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Syslifters SysReptor | <= 2026.61 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2026 | New CVE Received | [email protected] |
Volerion