CVE-2026-71302: Toptech TMS7 and TopHAT Session Fixation
The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Toptech TMS7 and TopHATto a version that resolves this vulnerability.Fixed in 7.8
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs network access and does not require prior privileges. Exploitation requires user interaction: a victim must authenticate using a session identifier the attacker has preselected.
What could a successful session takeover allow?
A successful attacker can reuse the authenticated victim session. The reported impact includes high confidentiality and integrity impact, with low availability impact.