CVE-2026-92920: admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled

Published Sep 17, 2026
·
Updated

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authenticate requests, as the AuthInterceptor never re-validates the user's locked status and session expiry resets on each request.

Affected Software

1 affected component
admin3>0<3.0.0

Event History

Sep 17, 2026
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker needs a bearer token that was issued to a user before that account is disabled. They can then continue sending authenticated requests with the token and retain the account's original permissions.

2

Are users who authenticate after their account is disabled affected?

The issue concerns existing sessions and bearer tokens issued before disablement. The provided information does not establish that new authentication succeeds after an account has been disabled.

3

Why does disabling the account not end the attacker's access?

The AuthInterceptor does not re-check whether the user is locked when processing requests. Session expiry is also reset on each request, allowing continued use of the pre-disablement token.

4

How can administrators identify potentially affected access?

Review for bearer tokens or active sessions created before a user account was disabled, especially where requests from those sessions continued after the disablement event. The available information does not provide a separate detection mechanism or indicator.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203