Critical severity9.1NVD Advisory· Published Jan 28, 2026· Updated Jun 17, 2026
CVE-2025-69602
CVE-2025-69602
Description
A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing an attacker who can set or predict a session ID to potentially hijack an authenticated session.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3=62.0.0+ 2 more
- (no CPE)range: =62.0.0
- cpe:2.3:a:altumcode:66biolinks:62.0.0:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
1- gist.github.com/Waqar-Arain/c8117308325a91b8f3b7829646915275nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.