PT-2026-94249 · Cjbi+1 · Admin3

·

CVE-2026-92918

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions admin3 version 3.0.0
Description User session tokens are persisted in the audit log event body during the publishing of UserLoggedIn domain events. An attacker with log:view permission can access these tokens by reading the JSON response from the 'GET /logs' endpoint. These harvested tokens can then be replayed as bearer credentials to gain full unauthorized access to user accounts.
Recommendations Update admin3 to a version newer than 3.0.0. Restrict the log:view permission to minimize the risk of session token exposure.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92918

Affected Products

Admin3