CVE-2026-39924

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 16:16

Updated : 2026-09-09 20:35


NVD link : CVE-2026-39924

Mitre link : CVE-2026-39924

CVE.ORG link : CVE-2026-39924


JSON object : View

Products Affected

No product.

CWE
CWE-613

Insufficient Session Expiration