CVE-2026-34572 describes a critical access control vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, affecting versions prior to 0.31.0.0. The flaw allows deactivated user accounts to retain indefinite access to the system because active sessions are not immediately terminated upon account deactivation, only during subsequent login attempts. This vulnerability is rated 8.8 High on the CVSS scale, indicating it is network-exploitable with low privileges and can lead to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code available, the issue has received minor community discussion. This represents a significant security flaw that breaks intended access control policies.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.31.0.0CPE matchmatch criteria | cpe:2.3:a:ci4-cms-erp:ci4ms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.