CVE-2026-34570Disclosure(ci4-cms-erp / ci4ms)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access. This issue has been patched in version 0.31.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-613CWE-1254

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
ci4ms

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-03: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 104-0204-03
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure1General1
2026-04-031
Disclosure1
Full discourse3 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34570: CI4MS: Account Deletion Module F... Deleted accounts maintain full system access indefinitely—classic session invalidation fail turns account deletion into... https://zerodaysignal.com/vulnerability/CVE-2026-34570 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑34570, describing a session‑invalidation flaw that allows deleted accounts to keep system access, but provides no exploit code, active‑use data, or patch information.

    0000054
    197 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-34570 | CVSS 10.0 🔴 CVE-2026-4370 | CVSS 10.0 🔴 CVE-2026-34569 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet merely highlights three new CVEs with high CVSS scores and provides a link to a vulnerability portal, offering no further details about exploitation, PoC, or mitigation.

    0000025
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34570 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.… https://www.cve.org/CVERecord?id=CVE-2026-34570

    Post summary

    The text identifies CVE‑2026‑34570 as affecting CI4MS versions prior to 0.31.0 but gives no details on exploitation, patches, or technical specifics.

    00000129
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more