Session Freshness Flaw in Flask-Security-Too by Pallets
CVE-2026-46715

5.3MEDIUM

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-46715?

A vulnerability in Flask-Security-Too version 5.8.0 allows an attacker to exploit the OAuth reauthentication flow. By using an already-authenticated but stale victim session, the attacker can mislead the system into treating their session as fresh. This could enable unauthorized actions that require freshness, compromising the integrity of the user's account. Version 5.8.1 has addressed this issue, reinforcing session management protocols.

Affected Version(s)

Flask-Security-Too >= 5.8.0, < 5.8.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.