Common Weakness Enumeration

    CWE Definition / CWE-384

    CWE-384: Session Fixation

    Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere

    CWE-346: Origin Validation Error

    CWE-472: External Control of Assumed-Immutable Web Parameter

    CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')