PT-2026-94251 · Cjbi+1 · Admin3
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
admin3 version 3.0.0
Description
The software fails to invalidate existing sessions when a user account is disabled, which allows attackers to maintain authenticated access with original permissions. Attackers can use bearer tokens issued before the account was disabled to authenticate requests because the
AuthInterceptor function does not re-validate the locked status of the user, and the session expiry is reset upon each request.Recommendations
Update admin3 to a version newer than 3.0.0.
As a temporary mitigation, restrict the use of the
AuthInterceptor or manually invalidate all active bearer tokens when disabling a user account.Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admin3