Improper Session Invalidation in Flarum by Flarum Inc.
CVE-2026-39924

7.6HIGH

Key Information:

Vendor

Flarum

Vendor
CVE Published:
5 August 2026

What is CVE-2026-39924?

Flarum prior to version 1.8.16 is affected by an improper session invalidation vulnerability. This issue allows attackers with valid session tokens to maintain full access to user accounts even after victims change their passwords. The vulnerability arises because the system fails to clear the access_tokens table during password changes, leaving active session cookies and API bearer tokens intact, including persistent RememberAccessToken entries. Consequently, administrative actions such as forced password resets do not affect sessions held by unauthorized users, which poses a significant security risk to Flarum users.

Affected Version(s)

Flarum Framework 0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hamed Kohi
VulnCheck
.