Impact
The vulnerability is that admin3, version 3.0.0, does not invalidate user sessions when an account is disabled. As a result, bearer tokens issued before disabling remain valid and continue to grant access, because the interceptor never re‑validates the locked status and session expiry is reset on each request. This flaw allows an attacker or a legitimate user who has previously authenticated to continue exercising the permissions of the disabled account without re‑authentication. The weakness is an insecure session handling vulnerability (CWE‑613).
Affected Systems
The affected product is admin3, a web‑based application by CJBI, for all releases up to and including 3.0.0. The vulnerability applies to the version range 1.x to 3.0.0, as all of those use the same AuthInterceptor implementation. Administrators running admin3 3.0.0 or any older release should consider the impact when disabling user accounts. No other vendors or product versions are mentioned.
Risk and Exploitability
The CVSS base score of 5.3 reflects a medium severity. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the current evidence of exploitation is low, but the design flaw permits continued use of valid tokens, which could enable privilege abuse or data exfiltration if the attacker retains a costly credential. The attack path requires an attacker to first obtain or reuse a bearer token issued before the account is disabled. Once the token is in hand, the attacker can send authenticated requests indefinitely, bypassing the disabled status check. There is no additional prerequisite beyond a usable token, so the exploitability is straightforward.
OpenCVE Enrichment