Insufficient Session Expiration in Flame Product by Pawel Malak
CVE-2026-100502
5.9MEDIUM
What is CVE-2026-100502?
The Flame product version 2.4.0 is affected by a vulnerability in its login endpoint that allows individuals with previous administrative access to exploit token management. By providing unvalidated parameters for session duration, attackers can generate tokens with prolonged lifespans, effectively creating near-permanent administrative access. This vulnerability arises because the tokens are verified using a static JWT secret that remains unchanged, allowing attackers to maintain control over the dashboard even after password resets.
Affected Version(s)
flame 0 <= 2.4.0
