No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bludit
Bludit bludit |
|
| Vendors & Products |
Bludit
Bludit bludit |
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a user account, the application fails to invalidate or clear the associated tokenAuth and tokenRemember fields in the JSON database. Consequently, any user with a pre-existing "Remember Me" cookie can bypass the account disablement and maintain a valid authenticated state. Version 3.22.0 patches the issue. | |
| Title | Bludit's persistent authentication tokens not revoked upon account disablement | |
| Weaknesses | CWE-212 CWE-613 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-08T16:29:49.605Z
Reserved: 2026-05-15T20:11:54.585Z
Link: CVE-2026-46657
Updated: 2026-06-08T16:29:46.025Z
Status : Received
Published: 2026-06-08T16:16:43.033
Modified: 2026-06-08T17:16:52.130
Link: CVE-2026-46657
No data.
OpenCVE Enrichment
Updated: 2026-06-08T16:45:26Z