LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-46656

Published
CVSS8.8
Severityhigh
WeaknessCWE-285
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthorized access to the system. Version 3.22.0 fixes the issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-46656

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-46656.