Loading market data...
← Back to CVE feed

CVE-2026-102367

MEDIUM CVSS 5.4 View on NVD ↗

Description

mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Published: Sep 29, 2026 00:17 UTC Modified: Sep 29, 2026 18:17 UTC