Insufficient Session Expiration in Flame Product by Pawel Malak
CVE-2026-100502

5.9MEDIUM

Key Information:

Vendor

Pawelmalak

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-100502?

The Flame product version 2.4.0 is affected by a vulnerability in its login endpoint that allows individuals with previous administrative access to exploit token management. By providing unvalidated parameters for session duration, attackers can generate tokens with prolonged lifespans, effectively creating near-permanent administrative access. This vulnerability arises because the tokens are verified using a static JWT secret that remains unchanged, allowing attackers to maintain control over the dashboard even after password resets.

Affected Version(s)

flame 0 <= 2.4.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Whispergate Security Research
.