CVE-2026-102367

Source
https://cve.org/CVERecord?id=CVE-2026-102367
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102367.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102367
Published
2026-09-28T23:34:31Z
Modified
2026-09-30T03:47:07Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
mall4j through 4.0 Insufficient Session Expiration via Token Refresh
Details

mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-613"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102367.json"
}
References

Affected packages

Git / github.com/gz-yami/mall4j

Affected ranges

Type
GIT
Repo
https://github.com/gz-yami/mall4j
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "4.0"
        },
        {
            "introduced":  "mall4j"
        },
        {
            "fixed":  "4.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102367.json"