{"id":"CVE-2026-39924","title":"Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is nev…","summary":"Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is nev…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-613"],"vendor":"Flarum","product":"Flarum Framework","affected":["framework < 1.8.16"],"published":"2026-08-05","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:35:08.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-39924","references":[{"url":"https://github.com/flarum/framework/commit/5f080293a029d0d273eb9678d597c74ea86a3bcc","label":"disclosure@vulncheck.com"},{"url":"https://github.com/flarum/framework/pull/4546","label":"disclosure@vulncheck.com"},{"url":"https://github.com/flarum/framework/releases/tag/v1.8.16","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/flarum-session-persistence-via-improper-access-token-revocation","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-05T15:48:45.636552Z"},"ingestedAt":"2026-09-10T19:07:39.284Z","epss":0.00373,"epssPercentile":0.28522,"slug":"CVE-2026-39924","body":"## Overview\n\nFlarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}