Insufficient Session Expiration in Token Issuance for Hex.pm by Hexpm
CVE-2026-86698

2.3LOW

Key Information:

Vendor

Hexpm

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-86698?

The vulnerability allows users whose organization membership or session has ended to retain access to private packages and documentation tarballs through a retained refresh token. The refresh token generation process within Hex.pm signs these tokens with the same claims as the access tokens, leading to a critical oversight. Consequently, users can maintain read-only access to organizational resources until their refresh token expires, which could take up to 30 days, despite their membership status having changed. This flaw highlights serious implications for organizational data privacy and security.

Affected Version(s)

hexpm 2025-10-10 < 2026-09-22

hexpm 650faa03af511e74c1b3b49ec12d35666b6984c4

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Männchen / EEF
Eric Meadows-Jönsson
.