Session Fixation Vulnerability in MISP CustomAuth Authentication
CVE-2026-85238
What is CVE-2026-85238?
MISP is affected by a session fixation vulnerability in its CustomAuth authentication process. This issue arises when an attacker manipulates a victim into using a session identifier that the attacker already knows. After the victim successfully authenticates, the session identifier remains unchanged, allowing the attacker to exploit the fixed session to gain unauthorized access to the victim's MISP session and associated privileges. The vulnerability stems from the improper management of session identifiers during authentication, specifically within the custom authentication flow, which did not rotate the session on user login. A patch has been implemented to restore proper session identifier rotation during authentication, enhancing security and preventing potential exploits.
Affected Version(s)
misp 0 <= 2.5.45
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
