CVE-2026-32745: Medium severity JetBrains Datalore vulnerability
Published Mar 13, 2026
·Updated
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
Affected Software
2 affected components
JetBrains Datalore<2026.1
JetBrains Datalore<2026.1
Event History
Mar 13, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-32745?
CVE-2026-32745 is categorized as a medium severity vulnerability due to session hijacking risks.
2
How do I fix CVE-2026-32745?
To fix CVE-2026-32745, upgrade to JetBrains Datalore version 2026.1 or later.
3
What kind of attacks are possible with CVE-2026-32745?
CVE-2026-32745 allows attackers to hijack user sessions by exploiting the lack of secure attributes in cookie settings.
4
Who is affected by CVE-2026-32745?
Any users of JetBrains Datalore versions prior to 2026.1 are affected by CVE-2026-32745.
5
Is there a workaround for CVE-2026-32745?
There is no specific workaround for CVE-2026-32745; patching to the latest version is recommended.