Junglewise Threat Intelligence

CVE-2026-41891: CI4MS has a Deactivated User Session Bypass (active=0)

CVE-2026-41891 · Severity: medium · CVSS 4 · Published 2026-05-04

Technologies: ci4-cms-erp/ci4ms (Packagist). Vendors: Packagist.

Executive brief

CI4MS has a Deactivated User Session Bypass (active=0)

Affected products

  • Packagist ci4-cms-erp/ci4ms

Related threats