PT-2026-5188 · Unknown · 66Biolinks

Published

2026-01-28

·

Updated

2026-02-09

·

CVE-2025-69602

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions 66biolinks version 62.0.0
Description The application does not regenerate the session identifier after successful authentication, leading to a session fixation issue. This allows an attacker who can set or predict a session ID to potentially hijack an authenticated session, as the same session cookie value is reused for users logging in from the same browser.
Recommendations Update to a newer version that regenerates the session identifier after successful authentication.

Exploit

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2025-69602

Affected Products

66Biolinks