CVE-2026-46656

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthorized access to the system. Version 3.22.0 fixes the issue.
Configurations

No configuration.

History

08 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 16:16

Updated : 2026-06-08 16:16


NVD link : CVE-2026-46656

Mitre link : CVE-2026-46656

CVE.ORG link : CVE-2026-46656


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization

CWE-613

Insufficient Session Expiration