Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode to invalidate persistent qasession cookies, the forgot-password handler qafinishresetuser() omits this step, allowing any valid persistent cookie issued before the reset to continue authenticating the account after the password reset completes.
{
"cwe_ids": [
"CWE-613"
],
"cna_assigner": "VulnCheck",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64829.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.8"
},
{
"introduced": "Question2Answer"
},
{
"fixed": "1.8.8"
}
],
"source": [
"AFFECTED_FIELD",
"DESCRIPTION"
]
}