A vulnerability marked as critical has been reported in HMS Ewon Flexy. This affects an unknown function of the component Session Cookie Handler. This manipulation causes improper authentication.

The identification of this vulnerability is CVE-2026-25818. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.