The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 21:16
Updated : 2026-09-15 21:16
NVD link : CVE-2026-66372
Mitre link : CVE-2026-66372
CVE.ORG link : CVE-2026-66372
JSON object : View
Products Affected
No product.
CWE
CWE-337
Predictable Seed in Pseudo-Random Number Generator (PRNG)
