For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
References
Configurations
No configuration.
History
17 Sep 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-384 |
17 Sep 2026, 10:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-17 10:17
Updated : 2026-09-17 16:17
NVD link : CVE-2026-78428
Mitre link : CVE-2026-78428
CVE.ORG link : CVE-2026-78428
JSON object : View
Products Affected
No product.
CWE
CWE-384
Session Fixation
