PT-2026-99133 · Flame · Flame

CVE-2026-100502

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Flame versions prior to 2.4.1
Description An insufficient session expiration issue exists in the login endpoint. Attackers with former administrator access can obtain tokens with arbitrary lifespans by providing unvalidated duration parameters. This allows the creation of near-permanent administrator tokens that persist even after password changes, granting full control of the dashboard because tokens are verified using a static JWT (JSON Web Token) secret that is never rotated.
Recommendations Update to a version newer than 2.4.0. Restrict access to the login endpoint to prevent unauthorized token requests.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100502

Affected Products

Flame