Description
admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authenticate requests, as the AuthInterceptor never re-validates the user's locked status and session expiry resets on each request.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Session Persistence
Action: Apply Patch
AI Analysis

Impact

The vulnerability is that admin3, version 3.0.0, does not invalidate user sessions when an account is disabled. As a result, bearer tokens issued before disabling remain valid and continue to grant access, because the interceptor never re‑validates the locked status and session expiry is reset on each request. This flaw allows an attacker or a legitimate user who has previously authenticated to continue exercising the permissions of the disabled account without re‑authentication. The weakness is an insecure session handling vulnerability (CWE‑613).

Affected Systems

The affected product is admin3, a web‑based application by CJBI, for all releases up to and including 3.0.0. The vulnerability applies to the version range 1.x to 3.0.0, as all of those use the same AuthInterceptor implementation. Administrators running admin3 3.0.0 or any older release should consider the impact when disabling user accounts. No other vendors or product versions are mentioned.

Risk and Exploitability

The CVSS base score of 5.3 reflects a medium severity. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the current evidence of exploitation is low, but the design flaw permits continued use of valid tokens, which could enable privilege abuse or data exfiltration if the attacker retains a costly credential. The attack path requires an attacker to first obtain or reuse a bearer token issued before the account is disabled. Once the token is in hand, the attacker can send authenticated requests indefinitely, bypassing the disabled status check. There is no additional prerequisite beyond a usable token, so the exploitability is straightforward.

Generated by OpenCVE AI on September 17, 2026 at 21:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑issued patch that implements session invalidation for disabled accounts; upgrade admin3 to the fixed release immediately.
  • If no patch is available, manually invalidate the session store for the disabled user by clearing records from the LocalSessionManager or its database table, and require the user to re‑authenticate to obtain a new token.
  • Add an additional check in the AuthInterceptor (or a custom middleware) that verifies the user’s enabled status on every request, forcing re‑authentication when an account is disabled.

Generated by OpenCVE AI on September 17, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cjbi
Cjbi admin3
Vendors & Products Cjbi
Cjbi admin3

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authenticate requests, as the AuthInterceptor never re-validates the user's locked status and session expiry resets on each request.
Title admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:57.685Z

Reserved: 2026-09-17T11:07:29.772Z

Link: CVE-2026-92920

cve-icon Vulnrichment

Updated: 2026-09-17T14:07:33.384Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T13:17:01.320

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:31Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration