Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bludit
Bludit bludit |
|
| Vendors & Products |
Bludit
Bludit bludit |
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a user account, the application fails to invalidate or clear the associated tokenAuth and tokenRemember fields in the JSON database. Consequently, any user with a pre-existing "Remember Me" cookie can bypass the account disablement and maintain a valid authenticated state. Version 3.22.0 patches the issue. | |
| Title | Bludit's persistent authentication tokens not revoked upon account disablement | |
| Weaknesses | CWE-212 CWE-613 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-08T16:29:49.605Z
Reserved: 2026-05-15T20:11:54.585Z
Link: CVE-2026-46657
Updated: 2026-06-08T16:29:46.025Z
Status : Deferred
Published: 2026-06-08T16:16:43.033
Modified: 2026-06-09T13:57:49.980
Link: CVE-2026-46657
No data.
OpenCVE Enrichment
Updated: 2026-06-08T16:45:26Z