CVE-2026-81181: SysReptor: Session Fixation in Password-Protected Shared Notes
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. An attacker who can obtain an unauthenticated SysReptor session cookie, place it in a victim's browser, and know the shared-note URL where the victim authenticates can reuse the fixed session after the victim enters the correct password and access that shared note. The main SysReptor login flow is not affected. This issue is fixed in version 2026.68.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SysReptorto a version that resolves this vulnerability.Fixed in 2026.68
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of SysReptor before version 2026.68 are affected only for password-protected shared notes. The main SysReptor login flow is not affected.
What must an attacker do to exploit it?
The attacker must obtain an unauthenticated SysReptor session cookie, cause that cookie to be used in the victim's browser, and know the URL of the password-protected shared note. After the victim enters the correct note password, the attacker can reuse the unchanged session to access that shared note.
How can this be remediated?
Upgrade SysReptor to version 2026.68, which rotates the session identifier after successful authentication for protected shared notes.