CVE-2025-59786

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
04/03/2026
Last modified:
05/03/2026

Description

2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*:* 3.5 (excluding)


References to Advisories, Solutions, and Tools