CVE-2025-59786Disclosure(2n / access_commander)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • access_commander

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
access_commander

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-04: 3Mentions · 2026-03-05: 1Technical Details · 2026-03-04: 3Technical Details · 2026-03-05: 103-0403-05
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-043
Disclosure3
2026-03-051
Disclosure1
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-59786 - Critical 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application. https://www.thehackerwire.com/vulnerability/CVE-2025-59786/ https://t.co/OzqEmsa5x8

    Post summary

    The tweet announces a newly identified CVE (2025-59786) affecting 2N Access Commander, describing a session token invalidation flaw without providing patches, exploits, or evidence of active exploitation.

    0000072
    124 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-59786 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application. https://www.cve.org/CVERecord?id=CVE-2025-59786

    Post summary

    CVE-2025-59786 is a disclosed vulnerability in 2N Access Commander 3.4.2 and earlier, where session tokens are not properly invalidated, allowing multiple session cookies to remain active after logout.

    00000198
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-59786 Session Token Invalidation Vulnerability in 2N Access Commander Web Application https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-59786

    Post summary

    The post announces the discovery of CVE‑2025‑59786, a session token invalidation vulnerability in 2N Access Commander’s web application.

    0000074
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-59786 - Cookies are not Invalidated upon Logout and Password Change Intel Report: https://ift.tt/VxroiHl

    Post summary

    The alert announces CVE-2025-59786, describing how session cookies persist after logout or password changes, potentially enabling session hijacking, but it offers no exploit or mitigation details.

    0000093
    344 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App2naccess_commander---

Explore more