Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-05 16:16
Updated : 2026-09-09 20:35
NVD link : CVE-2026-39924
Mitre link : CVE-2026-39924
CVE.ORG link : CVE-2026-39924
JSON object : View
Products Affected
No product.
CWE
CWE-613
Insufficient Session Expiration
