CVE-2026-92920Medium· 5.4▾ Sunlitadmin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disab…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authenticate requests, as the AuthInterceptor never re-validates the user's locked status and session expiry resets on each request.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92919High· 8.1admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments
CVE-2026-92921Medium· 4.9admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function
CVE-2026-92918High· 8.8admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events
CVE-2026-86698Low· 2.3Refresh tokens accepted as private repository credentials at the CDN
CVE-2026-79317Medium· 4.8A session invalidation flaw exists in x-ui 0.3.2
CVE-2026-77519Medium· 5.4MaxKB is an open-source AI assistant for enterprise