CVE-2026-102367 PUBLISHED

mall4j through 4.0 Insufficient Session Expiration via Token Refresh

Assigner: VulnCheck
Reserved: 28.09.2026 Published: 28.09.2026 Updated: 28.09.2026

mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor gz-yami
Product mall4j
Versions Default: unaffected
  • affected from 0 to 4.0 (incl.)

Credits

  • Mingsheng Lin finder

References

Problem Types

  • Insufficient Session Expiration CWE