Executive brief
Bludit, a content management system used for building websites, contains a security flaw where user sessions remain active even after an account has been deleted or disabled. This allows a removed user to maintain full access to the website, potentially allowing them to steal data, modify content, or create new administrative accounts to regain permanent control. Organizations using Bludit should update to version 3.22.0 to ensure that revoked users are immediately disconnected.
Technical details
Bludit CMS prior to version 3.22.0 suffers from improper authorization (CWE-285) and insufficient session expiration (CWE-613) within the isLogged() function in bl-kernel/login.class.php. The application relies on server-side session state (the $_SESSION global variable) without re-validating the user's existence or status against the database for subsequent requests. An attacker with an existing session can maintain access even after their account is physically deleted from the JSON database. This allows for persistent unauthorized actions, including privilege escalation by creating new administrative accounts from a deleted session. The issue is resolved in version 3.22.0 by modifying isLogged() to verify the subject's legitimacy against the user database for every request.
Affected products
- Bludit Bludit < 3.22.0
Timeline
- 2026-05-11: patched: Version 3.22.0 released
- 2026-05-19: advisory: GitHub Security Advisory published
- 2026-06-08: disclosed: CVE published to NVD