An attacker can maintain full account access & bypass administrative deactivation via improper session invalidation (broken access control / logic flaw), where active sessions are not revoked after an account is deactivated, allowing continued access to the application until manual logout
An attacker can maintain full account access & bypass administrative deactivation via improper session invalidation (broken access control / logic flaw), where active sessions are not revoked after an account is deactivated, allowing continued access to the application until manual logout