Description
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Account Takeover
Action: Immediate Patch
AI Analysis

Impact

admin3 (v3.0.0 and earlier) stores user session tokens in the audit log event body when publishing UserLoggedIn events. An attacker who can read the JSON response from the GET /logs endpoint can harvest these tokens and replay them as bearer credentials, thereby gaining full access to the user account. This vulnerability directly enables unauthorized account takeover and is classified under CWE-532, a serious data disclosure flaw. The CVSS score of 8.7 categorizes it as high severity.

Affected Systems

The affected product is admin3 from the vendor cjbi, specifically all releases up through version 3.0.0. Users running any of these versions are vulnerable if they have audit logs enabled and if session tokens are logged.

Risk and Exploitability

The vulnerability is high severity (CVSS 8.7) but currently has no EPSS score available and is not listed in the CISA KEV catalog. The attack requires the attacker to possess log:view permission, which typically means internal or compromised access. Once that privilege is attained, the attacker can easily retrieve session tokens via the GET /logs endpoint and reuse them as bearer tokens to impersonate any user. The lack of exploit data suggests the exploit is feasible but may not yet be widely used. Therefore, the risk is high for organizations that grant log viewing rights broadly or do not enforce strict role separation.

Generated by OpenCVE AI on September 18, 2026 at 06:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest admin3 release that removes session tokens from audit logs, or contact the vendor for an official patch.
  • Restrict the log:view permission to only trusted administrators, disallowing ordinary users from viewing audit logs until the patch is applied.
  • If an official patch is unavailable, configure or modify DefaultSessionService (or related logging configuration) so that session tokens are excluded from the audit log event body, and verify the change by inspecting sample log entries.

Generated by OpenCVE AI on September 18, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cjbi
Cjbi admin3
Vendors & Products Cjbi
Cjbi admin3

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access.
Title admin3 through 3.0.0 Session Token Disclosure via Audit Log
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:55.629Z

Reserved: 2026-09-17T11:07:29.772Z

Link: CVE-2026-92918

cve-icon Vulnrichment

Updated: 2026-09-17T12:38:08.155Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T13:17:01.013

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:35Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File