PT-2026-47329 · Bludit · Bludit

CVE-2026-46657

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bludit versions prior to 3.22.0
Description A flaw in the user management logic allows deactivated accounts to maintain access through persistent authentication tokens. When an administrator disables a user account, the application does not invalidate or clear the tokenAuth and tokenRemember fields within the JSON database. This allows users with an existing Remember Me cookie to bypass the account disablement and remain authenticated.
Recommendations Update to version 3.22.0.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46657
GHSA-GGQG-XVX6-HGWH

Affected Products

Bludit