By weakness (CWE)

CWE-212: related vulnerabilities

CVEs classified under CWE-212. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

3 published vulnerabilities

  • CVE-2026-46657HIGH 7.1

    Bludit, a content management system, contains a flaw in how it handles user account deactivation. When an administrator disables a user account, the system fails to clear the authentication tokens stored locally. This means a user who previously selected "Remember Me" can continue accessing the system even after their account has been disabled by an administrator. The vulnerability requires the attacker to have had legitimate access before being deactivated, but once disabled, they can maintain that access indefinitely unless the underlying token data is manually cleared.

  • CVE-2026-54421MEDIUM 6.8

    OpenStack Ironic has a flaw where PATCH requests to update volume property fields can leak sensitive credentials like iSCSI usernames and passwords to authorized users. This is a privilege-aware vulnerability—only users with authorization to modify those fields can trigger the leak, and only through PATCH operations, not POST. The issue affects Ironic versions before 37.0.1.

  • CVE-2026-36178MEDIUM 4.6

    A flaw in the factory reset process of GNCC GP5 v7.1.76 leaves sensitive cryptographic keys and related data intact on the device's storage partition even after a factory reset is performed. An attacker with physical access to the device could potentially recover this material and use it to decrypt or impersonate the original user's configuration and encrypted content.