PT-2026-37161 · Ci4Ms · Ci4Ms

·

CVE-2026-41891

·

Published

2026-05-04

·

Updated

2026-05-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CI4MS versions 0.26.0 through 0.31.7.0
Description The auth filter contains commented-out code for checking if a user is deactivated or banned. While the loggedIn() function in CodeIgniter Shield verifies the status field to identify banned users, it does not re-verify the active field for existing sessions. Consequently, if an administrator deactivates a user by setting active to 0 after the user has already authenticated, the session cookie remains valid and auth()->loggedIn() continues to return true. This allows a deactivated user to maintain full backend access until their session expires.
Recommendations Update to version 0.31.8.0.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41891
GHSA-5HFV-C864-QCQ9

Affected Products

Ci4Ms