CVE-2026-24894 | php franken up to 1.11.1 session_start $_SESSION privileges management (GHSA-r3xh-3r3w-47gp)
A vulnerability marked as critical has been reported in php franken up to 1.11.1. Affected by this issue is the function session_start. The manipulation of the argument $_SESSION leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2026-24894. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.