CVE-2026-2439Patch(bva / concierge\)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch bva concierge\ systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using Perl's built-in rand function. Neither of these methods are secure, and attackers are able to guess session_ids that can grant them access to systems. Specifically, * There is no warning when uuidgen fails. The software can be quietly using the fallback rand() function with no warnings if the command fails for any reason. * The uuidgen command will generate a time-based UUID if the system does not have a high-quality random number source, because the call does not explicitly specify the --random option. Note that the system time is shared in HTTP responses. * UUIDs are identifiers whose mere possession grants access, as per RFC 9562. * The output of the built-in rand() function is predictable and unsuitable for security applications.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338CWE-340

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • concierge\

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-16); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
concierge\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-16: 2Mentions · 2026-02-17: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-16: 2Technical Details · 2026-02-17: 102-1602-17
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-162
Disclosure1Patch1
2026-02-171
Patch1
Full discourse3 posts
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-2439 hits BVA Concierge::Sessions 0.8.1 – 0.8.4! Weak session IDs = easy session hijack. Upgrade now or risk unauthorized access. 🛡️ https://radar.offseq.com/threat/cve-2026-2439-cwe-340-generation-of-predictable-nu-8847b5d6 #OffSeq #CVE20262439 #infosec https://t.co/18BStbFAsV

    Post summary

    The tweet highlights a critical vulnerability (CVE‑2026‑2439) in BVA Concierge::Sessions caused by weak session IDs that allow hijacking, and urges users to upgrade to mitigate the risk.

    0000045
    265 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2439 Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to u… https://www.cve.org/CVERecord?id=CVE-2026-2439

    Post summary

    The post announces that Concierge::Sessions versions 0.8.1 to 0.8.4 in Perl generate insecure session IDs because the generate_session_id function defaults to an unsafe value.

    00000735
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity: CVE-2026-2439 in BVA Concierge::Sessions 0.8.1-0.8.4 lets attackers predict session IDs, risking unauthorized access! Upgrade ASAP or use secure RNGs. https://radar.offseq.com/threat/cve-2026-2439-cwe-340-generation-of-predictable-nu-8847b5d6 #OffSeq #Cybersec... https://t.co/hjRHuIM22T

    Post summary

    CVE‑2026‑2439 permits attackers to predict session IDs in BVA Concierge::Sessions 0.8.1‑0.8.4, potentially leading to unauthorized access. Users are urged to upgrade the software or implement secure random number generators as a mitigation.

    0000033
    265 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbvaconcierge\\--

Explore more