Back to overview

CVE-2026-2439

CRITICAL
9.8
CVSS 3.1
Description
Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using Perl's built-in rand function. Neither of these methods are secure, and attackers are able to guess session_ids that can grant them access to systems. Specifically, * There is no warning when uuidgen fails. The software can be quietly using the fallback rand() function with no warnings if the command fails for any reason. * The uuidgen command will generate a time-based UUID if the system does not have a high-quality random number source, because the call does not explicitly specify the --random option. Note that the system time is shared in HTTP responses. * UUIDs are identifiers whose mere possession grants access, as per RFC 9562. * The output of the built-in rand() function is predictable and unsuitable for security applications.

Metadata

CVE ID
CVE-2026-2439
State
PUBLISHED
Assigner
CPANSec
Reserved
2026-02-12 23:47 UTC
Published
2026-02-16 21:25 UTC
Last updated
2026-02-17 14:45 UTC
Primary CWE
CWE-340
CWE-340 Generation of Predictable Numbers or Identifiers
Vendor / Product
BVA / Concierge::Sessions
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
BVA Concierge::Sessions 0.8.1 < 0.8.5
Weakness (CWE)
CWESourceDescription
CWE-338 cna CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CWE-340 cna CWE-340 Generation of Predictable Numbers or Identifiers
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview