Skip to content
devwallssecurity
A worn metal keypad on an entry device
research / DW-2026-004

Session fixation in a widely deployed identity broker

An attacker able to set a cookie on a subdomain could fix a victim's session identifier before authentication and inherit the authenticated session afterwards.

affected
Identity broker, versions 4.2 through 4.6.1
cvss v3.1
8.1
published
2026-07-14
status
Patched — disclosed after 90 days
critical
detail

The broker accepted a session identifier presented by the client at the start of the authentication flow and reused it after a successful login rather than issuing a fresh one. Any position allowing a cookie to be written on a shared parent domain was therefore sufficient to take over an account, with no interaction beyond the victim logging in normally.

We found this during a routine application security engagement for a client who had deployed the broker in front of forty internal services. The bug was in the broker, not in their configuration, so we took it to the vendor.

The vendor shipped a fix in 4.6.2 which rotates the identifier on privilege transition. If you cannot upgrade, terminating sessions at a reverse proxy that issues its own identifier is an effective mitigation.

timeline
  1. 2026-03-02
    Discovered during client engagement
  2. 2026-03-04
    Reported to vendor with proof-of-concept
  3. 2026-03-05
    Vendor acknowledged
  4. 2026-04-18
    Fix shipped in 4.6.2
  5. 2026-07-14
    Public disclosure at 90 days
backall advisories
A dense city skyline at night, lit windows in red and amber

worried this affects you

If you run the affected product and are not sure whether you are exposed, send us the version and configuration. We will tell you, and there is no charge for that answer.