PT-2026-99133 · Flame · Flame
CVE-2026-100502
·
Published
2026-09-25
·
Updated
2026-09-26
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Flame versions prior to 2.4.1
Description
An insufficient session expiration issue exists in the login endpoint. Attackers with former administrator access can obtain tokens with arbitrary lifespans by providing unvalidated duration parameters. This allows the creation of near-permanent administrator tokens that persist even after password changes, granting full control of the dashboard because tokens are verified using a static JWT (JSON Web Token) secret that is never rotated.
Recommendations
Update to a version newer than 2.4.0.
Restrict access to the login endpoint to prevent unauthorized token requests.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flame