CVE-2026-57948CWE-1004CWE-614

Pinpoint - Insecure Session Cookie Attributes in pinpointJwt

High · published June 29, 2026

CVSS v4.0
7.6
EPSS
0%
Percentile
10.0
In the wild
Unconfirmed
What it is

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.

The record
Technical detail
CVSS v4.0
7.6 · HIGH
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00202 · 10.0th percentile
Weaknesses
CWE-1004 · Sensitive Cookie Without 'HttpOnly' Flag; CWE-614 · Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Published
2026-06-29T17:19Z
EPSS history
Timeline
  • 29 JUN 17:19Z
    Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
    cvelistv5