Session Fixation Vulnerability in MISP CustomAuth Authentication
CVE-2026-85238

7.6HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85238?

MISP is affected by a session fixation vulnerability in its CustomAuth authentication process. This issue arises when an attacker manipulates a victim into using a session identifier that the attacker already knows. After the victim successfully authenticates, the session identifier remains unchanged, allowing the attacker to exploit the fixed session to gain unauthorized access to the victim's MISP session and associated privileges. The vulnerability stems from the improper management of session identifiers during authentication, specifically within the custom authentication flow, which did not rotate the session on user login. A patch has been implemented to restore proper session identifier rotation during authentication, enhancing security and preventing potential exploits.

Affected Version(s)

misp 0 <= 2.5.45

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andras Iklody
Scottish Government - National Cyber Team
Peter James
.