An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.
Use CWE-613, Nagios vendor hub and Network Analyzer product page to widen CVE-2025-28059 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-28925, CVE-2025-34280 and CVE-2021-28924 for nearby disclosures in the same product family. Additional editorial context is available in Why “Low” and “Medium” CVEs Still Breach Networks.