CVE-2026-92918 UNKNOWN

CVE-2026-92918

Published: 2026-09-17

Description

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…