2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
History

Thu, 05 Mar 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 05 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared 2n
2n access Commander
Vendors & Products 2n
2n access Commander

Wed, 04 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Description 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
Title Cookies are not Invalidated upon Logout and Password Change
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: 2N

Published: 2026-03-04T15:30:35.148Z

Updated: 2026-03-04T16:03:17.708Z

Reserved: 2025-09-19T17:22:49.648Z

Link: CVE-2025-59786

cve-icon Vulnrichment

Updated: 2026-03-04T16:03:11.804Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-04T16:16:25.453

Modified: 2026-03-05T14:30:45.357

Link: CVE-2025-59786

cve-icon Redhat

No data.