AllCyberNews

CVE-2026-71302

Toptech TMS7 and TopHAT Session Fixation

CVSS 7.5 high · Toptech Systems TMS7 · published 2026-09-29

The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.

Coverage 1 source

  1. 2026-09-29 CISA Cybersecurity Advisories high Toptech TMS7 and TopHAT

    Multiple vulnerabilities affect Toptech TMS7 and TopHAT versions 7.6.3.

Mentioned with

CVE-2026-63713 CVE-2026-68068 CVE-2026-68954 CVE-2026-69662 CVE-2026-70356 CVE-2026-71189 CVE-2026-71379 CVE-2026-72507 CVE-2026-72510

Also covered