Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authenticate requests, as the AuthInterceptor never re-validates the user's locked status and session expiry resets on each request. | |
| Title | admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled | |
| Weaknesses | CWE-613 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T14:08:17.695Z
Reserved: 2026-09-17T11:07:29.772Z
Link: CVE-2026-92920
No data.
Status : Received
Published: 2026-09-17T13:17:01.320
Modified: 2026-09-17T14:17:57.193
Link: CVE-2026-92920
No data.
OpenCVE Enrichment
No data.
-
CWE-613
Insufficient Session Expiration