PT-2026-85082 · Misp · Misp

·

CVE-2026-85238

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description A session fixation issue exists in the CustomAuth authentication flow. The system stores the authenticated user identity in the existing session without rotating the session identifier. This allows an attacker to use a pre-known session identifier to hijack a victim's authenticated session and gain their account privileges. The flaw occurs because the customAuthentication() function writes the user into the CakePHP session while the Session->renew() call is disabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85238

Affected Products

Misp