Generated remediation guidance and an executive summary. No account required.
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session.
Use CWE-613, Apostrophecms vendor hub and Apostrophecms product page to widen CVE-2021-25979 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-35569, CVE-2026-32730 and CVE-2026-40186 for nearby disclosures in the same product family.