Sceawere
Vulnerability Detail
CVE-2026-102367UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Insufficient Session Expiration in mall4j
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 7h ago
- Vendor
- gz-yami
- Product
- mall4j
- Attack Type
- Insufficient Session Expiration
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-29T00:17:04.060Z",
"pubdate": "2026-09-29T00:17:04.060Z",
"executiveSummary": "Mall4j versions through 4.0 are susceptible to an insufficient session expiration vulnerability within the authentication framework. The flaw resides in the token refresh mechanism, which fails to verify the account's 'enabled' status during the issuance of new session tokens.\nThe vulnerability allows users whose accounts have been administratively disabled to bypass access revocation by continuously utilizing the POST /token/refresh endpoint. By maintaining a valid refresh token, an attacker can generate new access tokens indefinitely, effectively rendering the administrative 'disable' function ineffective.\nThis represents a significant failure in identity and access management (IAM) enforcement, granting unauthorized continued access to restricted resources. An attacker with a previously valid refresh token requires no additional credentials to maintain persistent, illegitimate access, posing a substantial risk to data confidentiality and integrity within the platform.",
"technicalDetails": "The vulnerability originates from a logical flaw in the security validation routine governing the token refresh process. Within the mall4j authentication architecture, the POST /token/refresh endpoint is designed to issue new JWT-based access tokens upon the presentation of a legitimate refresh token.\nThe root cause is the omission of an account status verification check during the refresh cycle. While the initial authentication request likely validates the account's 'enabled' flag against the database or user store, the refresh controller performs no such lookup. It implicitly trusts the presence of a cryptographically valid refresh token as sufficient authorization to generate a new session.\nThe attack flow proceeds as follows: 1) A user establishes a legitimate session while the account is active. 2) An administrator subsequently flags the account as 'disabled' in the backend system to terminate access. 3) The attacker, possessing a non-expired refresh token, initiates a POST request to the /token/refresh endpoint. 4) The application logic validates the signature of the provided refresh token and, lacking a check against the user's enabled status, returns a new, active access token.\nThis creates a state of perpetual access persistence. Because the refresh token is not revoked server-side upon account disabling, the server continues to treat the user as authenticated despite the administrative override. This indicates a critical decoupling of the session management layer from the user identity management layer.\nThe scope of impact includes unauthorized access to protected API endpoints, sensitive data retrieval, and potential manipulation of system resources that the disabled user should no longer be able to touch. The vulnerability does not require complex payloads or exploitation of memory safety errors; it is purely a breakdown in access control logic that is easily triggered via standard HTTPS requests.\nAffected versions include all mall4j releases up to and including 4.0. Remediation requires ensuring that the refresh token verification process includes an explicit check against the current user account state in the persistent storage, ensuring that disabled accounts are immediately ineligible for session renewal."
}