PT-2026-83449 · Rodauth · Rodauth
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rodauth versions prior to 2.47.0
Description
An authentication bypass exists in the 'jwt refresh' endpoint. The system issues new JSON Web Tokens (JWT)—which are compact, URL-safe means of representing claims to be transferred between two parties—without requiring a refresh token. An attacker can provide an access token to this endpoint using non-POST methods to obtain a new valid access token, allowing for indefinite account access if a temporary token is possessed.
Recommendations
Update to version 2.47.0 or later.
Restrict access to the 'jwt refresh' endpoint to only allow POST methods as a temporary mitigation.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rodauth