CVE-2026-92918
8.8 HIGHpublic exploit availablePublished 2026-09-17 · Updated 2026-09-22
AI risk analysis
- Summary
- The flaw allows attackers with log:view permission to read session tokens from audit logs and use them for full user access, compromising session security.
- Exploitability
- Exploitation requires log:view permission but is relatively straightforward given the exposed endpoint.
- Blast radius
- If exploited, it could lead to unauthorized access and potential data breaches affecting all users with compromised session tokens.
- Prioritized remediation
- Restrict log:view permissions or remove persistence of session tokens in audit logs.
auth-bypasslog-abusesession-hijacking
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-532
Public exploit & PoC references
- https://github.com/LinYuanyi1/cve-request-poc/blob/master/admin3/C02_log_session_token_disclosure.py
- https://github.com/cjbi/admin3
- https://github.com/cjbi/admin3/blob/3.0.0/admin3-server/src/main/java/tech/wetech/admin3/infra/service/DefaultSessionService.java
- https://github.com/cjbi/admin3/blob/3.0.0/admin3-server/src/main/java/tech/wetech/admin3/sys/service/LogService.java
- https://github.com/cjbi/admin3/blob/3.0.0/admin3-server/src/main/resources/data.sql
All references
- https://github.com/LinYuanyi1/cve-request-poc/blob/master/admin3/C02_log_session_token_disclosure.py
- https://github.com/cjbi/admin3
- https://github.com/cjbi/admin3/blob/3.0.0/admin3-server/src/main/java/tech/wetech/admin3/infra/service/DefaultSessionService.java
- https://github.com/cjbi/admin3/blob/3.0.0/admin3-server/src/main/java/tech/wetech/admin3/sys/service/LogService.java
- https://github.com/cjbi/admin3/blob/3.0.0/admin3-server/src/main/resources/data.sql
- https://www.vulncheck.com/advisories/admin3-through-3.0.0-session-token-disclosure-via-audit-log
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-70486PoC
- HIGHCVE-2026-77614PoC
- CRITICALCVE-2025-15399
- HIGHCVE-2025-51457
- CRITICALCVE-2025-66455PoC
- HIGHCVE-2025-70962PoC
- MEDIUMCVE-2025-71420PoC
- CRITICALCVE-2026-10050PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.