Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 14 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flarum flarum
|
|
| CPEs | cpe:2.3:a:flarum:flarum:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flarum flarum
|
Fri, 07 Aug 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flarum
Flarum framework |
|
| Vendors & Products |
Flarum
Flarum framework |
Wed, 05 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions. | |
| Title | Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T16:49:48.743Z
Reserved: 2026-04-07T20:57:06.210Z
Link: CVE-2026-39924
Updated: 2026-08-05T15:48:52.839Z
Status : Received
Published: 2026-08-05T16:16:56.137
Modified: 2026-08-05T16:16:56.137
Link: CVE-2026-39924
No data.
OpenCVE Enrichment
Updated: 2026-08-07T09:30:11Z