2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Description 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
Title Cookies are not Invalidated upon Logout and Password Change
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: 2N

Published:

Updated: 2026-03-04T16:03:17.708Z

Reserved: 2025-09-19T17:22:49.648Z

Link: CVE-2025-59786

cve-icon Vulnrichment

Updated: 2026-03-04T16:03:11.804Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-04T16:16:25.453

Modified: 2026-03-04T18:08:05.730

Link: CVE-2025-59786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses