CVE-2026-46656

Source
https://cve.org/CVERecord?id=CVE-2026-46656
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46656.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-46656
Aliases
  • GHSA-rpq2-j9w3-h4jw
Published
2026-06-08T14:51:32.720Z
Modified
2026-08-04T11:51:01.385460495Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
Details

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthorized access to the system. Version 3.22.0 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-285",
        "CWE-613"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46656.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/bludit/bludit

Affected ranges

Type
GIT
Repo
https://github.com/bludit/bludit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.22.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

3.*
3.17.2
3.18.0
3.18.1
3.18.2
3.18.4
3.19.0
3.20.0
3.21.0
3.21.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46656.json"