CVE-2026-34570 details a critical improper access control vulnerability in CI4MS versions prior to 0.31.0.0. This flaw allows user accounts, even after being deleted, to retain indefinite access to the system via their active sessions due to a logic error that only enforces account state changes during login. Rated with a CVSS score of 10.0 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and requires no privileges or user interaction, leading to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code available, the vulnerability has received some attention within the cybersecurity community. Organizations using affected CI4MS versions should upgrade to 0.31.0.0 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.31.0.0CPE matchmatch criteria | cpe:2.3:a:ci4-cms-erp:ci4ms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.