Description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state changes are enforced only during authentication (login), not for already-established sessions. The system implicitly assumes that authenticated users remain trusted for the lifetime of their session. There is no session expiration or account expiration mechanism in place, causing deleted accounts to retain indefinite access until the user manually logs out. This behavior breaks the intended access control policy and results in persistent unauthorized access. This issue has been patched in version 0.31.0.0.

INFO

Published Date :

2026-04-01T21:30:31.415Z

Last Modified :

2026-04-06T17:15:53.691Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-34570 vulnerability.

Vendors Products
Ci4-cms-erp
  • Ci4ms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-34570.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact