CVE-2026-85238 | MISP up to 2.5.45 CustomAuth __customAuthentication session fixiation (e2eb2f058 / WID-SEC-2026-3173)
A vulnerability was found in MISP up to 2.5.45. It has been declared as critical. Affected is the function __customAuthentication of the component CustomAuth. Such manipulation leads to session fixiation.
This vulnerability is traded as CVE-2026-85238. The attack may be launched remotely. There is no exploit available.
A patch should be applied to remediate this issue.