CVE-2026-34572Disclosure(ci4-cms-erp / ci4ms)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch ci4-cms-erp ci4ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deactivated accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access, representing a critical security flaw. This issue has been patched in version 0.31.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-613CWE-1254

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
ci4ms

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-02: 3Patch / Workaround · 2026-04-02: 104-02
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34572: HIGH] CodeIgniter-based CMS CI4MS had a critical security flaw pre-v0.31.0.0. Deactivated accounts retained access due to an issue with session revocation. Update to the latest version to pa...#cve,CVE-2026-34572,#cybersecurity https://cvefind.com/CVE-2026-34572

    Post summary

    The message announces a high‑severity CVE affecting CodeIgniter’s CI4MS CMS that allows deactivated accounts to retain access, and urges users to update to the latest version to apply a patch.

    0000038
    617 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34572 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.… https://www.cve.org/CVERecord?id=CVE-2026-34572

    Post summary

    The snippet references CVE-2026-34572 and links to its CVE record, indicating a new disclosure for CI4MS. No further technical details, exploit code, or mitigation information is provided.

    00000140
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-34572 - High CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails ... https://www.thehackerwire.com/vulnerability/CVE-2026-34572/ https://t.co/uplXL2HHk2

    Post summary

    The tweet mentions CVE‑2026‑34572 as a high‑severity flaw in the CI4MS CMS but lacks technical, exploit, or remediation details.

    0000054
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more