← back
CVE-2026-44873mediumCWE-613

Insufficient Session Invalidation on User Account Deactivation in AOS-8 Operating System

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration. An attacker with compromised credentials could exploit this behavior to maintain unauthorized access even after the account has been disabled.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N