Loading market data...
← Back to CVE feed

CVE-2026-44873

MEDIUM CVSS 5.4 View on NVD ↗

Description

A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration. An attacker with compromised credentials could exploit this behavior to maintain unauthorized access even after the account has been disabled.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Published: May 12, 2026 20:16 UTC Modified: May 13, 2026 16:16 UTC