Session Management Flaw in Admin3 Product by CJBI
CVE-2026-92920
Key Information:
Badges
What is CVE-2026-92920?
The Admin3 product by CJBI contains a session management flaw where user sessions are not invalidated upon account deactivation. This allows attackers to maintain their previous authenticated status, thereby accessing resources with the user's original permissions. The vulnerability arises from the AuthInterceptor not verifying the user's account status, permitting the continued use of bearer tokens issued before the account disabling. As a result, even after an account is locked, the session remains active, leading to potential unauthorized access.
Affected Version(s)
admin3 0 <= 3.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
