CVE-2026-46656: Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthorized access to the system. Version 3.22.0 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bluditto a version that resolves this vulnerability.Fixed in 3.22.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46656?
CVE-2026-46656 has a severity rating of high, with a score of 8.8.
What kind of vulnerability is CVE-2026-46656?
CVE-2026-46656 is a Broken Access Control flaw in Bludit CMS that leads to improper authorization.
How do I fix CVE-2026-46656?
To fix CVE-2026-46656, update Bludit to version 3.22.0 or later.
What impact does CVE-2026-46656 have on users?
CVE-2026-46656 allows revoked users to maintain unauthorized access through ghost sessions.
Which versions of Bludit are affected by CVE-2026-46656?
Bludit versions prior to 3.22.0 are affected by CVE-2026-46656.