The product uses a scheme that generates numbers or identifiers that are more predictable than required.
Volume of CVEs assigned to CWE-340 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-11374CRITICAL In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted
by an unau | Jun 23, 2026 | 9.0 | 43 | NO | NO |
CVE-2026-5081CRITICAL Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure.
Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the v | May 6, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-13577HIGH Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable.
Dancer2::Core::Role::SessionFactory::generate_id silently falls | Jul 20, 2026 | 8.2 | 37 | NO | NO |
CVE-2026-9733CRITICAL Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter.
When no state generator is specified in the constructor, the module | Jun 23, 2026 | 9.1 | 37 | NO | NO |
CVE-2026-3256CRITICAL HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids.
HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids usi | Mar 28, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-2439CRITICAL Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uui | Feb 16, 2026 | 9.8 | 35 | NO | NO |
CVE-2025-15604CRITICAL Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions.
In versions 6.06 through 6.16, the random_string function will attempt to | Mar 28, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-9219MEDIUM Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authenti | Jun 26, 2026 | 6.5 | 31 | NO | NO |
CVE-2025-40926CRITICAL Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely.
The default session id generator returns a SHA-1 hash seeded with the built-in r | Mar 5, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-56016MEDIUM CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources.
The generate_id method builds the session id from a MD5 digest of th | Jul 1, 2026 | 5.9 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.