CVE-2025-59786

CRITICAL

2N Access Commander <3.4.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.

Scores

CVSS v3 9.8
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (1)
2n/access_commander < 3.5
Published Mar 04, 2026
Tracked Since Mar 04, 2026