CVE-2026-100502 PUBLISHED

Flame through 2.4.0 Admin Token Insufficient Session Expiration

Assigner: VulnCheck
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password changes, retaining full control of the dashboard since tokens are verified only against a static JWT secret that is never rotated.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.9

Product Status

Vendor pawelmalak
Product flame
Versions Default: unaffected
  • affected from 0 to 2.4.0 (incl.)

Credits

  • Whispergate Security Research finder

References

Problem Types

  • Insufficient Session Expiration CWE