A vulnerability categorized as critical has been discovered in Bludit up to 3.21.x. This issue affects some unknown processing of the component User Management Handler. Such manipulation of the argument tokenAuth/tokenRemember leads to improper removal of sensitive information before storage or transfer.

This vulnerability is referenced as CVE-2026-46657. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.