CVE-2026-92918

Source
https://cve.org/CVERecord?id=CVE-2026-92918
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92918.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92918
Published
2026-09-17T12:33:23Z
Modified
2026-09-19T03:47:29Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
admin3 through 3.0.0 Session Token Disclosure via Audit Log
Details

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-532"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92918.json"
}
References

Affected packages

Git / github.com/cjbi/admin3

Affected ranges

Type
GIT
Repo
https://github.com/cjbi/admin3
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0"
        },
        {
            "introduced": "admin3"
        },
        {
            "fixed": "3.0.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92918.json"