PT-2026-82628 · Flowintel · Flowintel

·

CVE-2026-81826

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Flowintel versions 3.3.0 and later
Description Authenticated sessions are not revoked when a user changes their password. This allows an attacker with a valid session token to maintain access to the account until the session expires naturally, even after the password has been updated. The issue occurs within the edit user core() and admin edit user core() functions, where the system fails to call invalidate user sessions(user.id) following a database update.
Recommendations Update Flowintel to a version where the edit user core() and admin edit user core() functions explicitly invoke invalidate user sessions(user.id) upon password changes.

Exploit

Fix

Session Fixation

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81826

Affected Products

Flowintel