CVE-2026-102367

Published: Set 29, 2026 Last Modified: Set 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,4
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: none

Description

AI Translation Available

mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.

613

Insufficient Session Expiration

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
https://github.com/gz-yami/mall4j
https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae…
https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae…
https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf804…
https://www.vulncheck.com/advisories/mall4j-through-4.0-insufficient-session-ex…