A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing an attacker who can set or predict a session ID to potentially hijack an authenticated session.
References
| Link | Resource |
|---|---|
| https://gist.github.com/Waqar-Arain/c8117308325a91b8f3b7829646915275 | Exploit Third Party Advisory |
Configurations
History
09 Feb 2026, 17:24
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Altumcode
Altumcode 66biolinks |
|
| References | () https://gist.github.com/Waqar-Arain/c8117308325a91b8f3b7829646915275 - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:altumcode:66biolinks:62.0.0:*:*:*:*:*:*:* |
29 Jan 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-384 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
28 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-28 19:16
Updated : 2026-02-09 17:24
NVD link : CVE-2025-69602
Mitre link : CVE-2025-69602
CVE.ORG link : CVE-2025-69602
JSON object : View
Products Affected
altumcode
- 66biolinks
CWE
CWE-384
Session Fixation
