Description
mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized session persistence from disabled accounts
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in mall4j 4.0 allows a disabled user account to maintain an active session by repeatedly calling the POST /token/refresh endpoint. The token refresh logic ignores the enabled flag, so the system issues a new session token even when the account is marked as inactive. This bypasses the intended access revocation mechanism, letting a user persist privileges after disabling, effectively turning the account into a long‑lived, unauthorized session – a classic example of improper restriction of operations (CWE‑613).

Affected Systems

Affected systems are all installations of the mall4j framework version 4.0 and below, provided by the vendor gz‑yami. The issue is present across all modules that expose the token refresh API, as seen in the source paths in the referenced repository. Clients that have not applied a newer release or have not patched the token store code are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. The exploit requires an existing session token for the disabled account, which can be obtained if an attacker has previously authenticated. There is no documented public exploit, and the EPSS value is not available, but the missing validation permits an attacker who can acquire a token to continuously refresh it. The vulnerability is not listed in CISA's KEV catalog, suggesting limited real‑world exploitation to date, though the impact on compromised accounts is significant.

Generated by OpenCVE AI on September 29, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest mall4j release (4.1 or later) where the token refresh endpoint validates the account enabled flag before issuing a new session.
  • If an update is not immediately possible, temporarily disable the token refresh functionality or modify the TokenController to reject refreshes for accounts marked as disabled until a patch is available.
  • Immediately audit user disabling procedures to ensure that all active tokens are invalidated when an account is disabled and monitor for repeated token refresh attempts from disabled accounts.

Generated by OpenCVE AI on September 29, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.
Title mall4j through 4.0 Insufficient Session Expiration via Token Refresh
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T23:34:31.264Z

Reserved: 2026-09-28T22:50:20.304Z

Link: CVE-2026-102367

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:04.060

Modified: 2026-09-29T00:17:04.060

Link: CVE-2026-102367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T00:30:08Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration