CVE-2026-100502: Flame through 2.4.0 Admin Token Insufficient Session Expiration

Published Sep 25, 2026
·
Updated

Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password changes, retaining full control of the dashboard since tokens are verified only against a static JWT secret that is never rotated.

Affected Software

1 affected component
Flame<=2.4.0

Event History

Sep 25, 2026
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs former administrator access and the ability to use the login endpoint to request a token. It is not described as exploitable by an unauthenticated or low-privileged user.

2

What access could a successful attacker retain?

The attacker can obtain an administrator token with an arbitrary, near-permanent lifetime and retain full dashboard control. The token can remain valid after password changes because verification relies on a static JWT secret that is not rotated.

3

How can I determine whether previously issued administrator tokens may still be valid?

Administrators should treat tokens issued to former administrators as potentially persistent if they could have supplied a custom duration parameter when logging in. Password changes alone do not invalidate these tokens under the described design.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203