Common Weakness Enumeration
CWE Definition / CWE-384
CWE-384: Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Published:19 Jul 2006
Organization:MITRE
Modified:11 Dec 2025
Related Weakness
CWE-610: Externally Controlled Reference to a Resource in Another Sphere
CWE-610: Externally Controlled Reference to a Resource in Another Sphere
CWE-346: Origin Validation Error
CWE-472: External Control of Assumed-Immutable Web Parameter
CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')
