PT-2026-47328 · Bludit · Bludit

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-46656

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthorized access to the system. Version 3.22.0 fixes the issue.

Exploit

Fix

Insufficient Session Expiration

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-46656

Affected Products

Bludit