CVE-2026-75171: HubCore vulnerability
Published Sep 4, 2026
·Updated
An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.
Affected Software
1 affected component
HubCore=14.1.1
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable. The available information does not state whether authentication or possession of a valid session is required.
2
Which component should be prioritized for investigation?
Investigate HubCore's handling of the HUBCOREID session cookie, as this is the component identified as enabling privilege escalation.
3
What affected version is identified?
HubCore version 14.1.1 is identified in the available information. No other affected or fixed versions are provided.