CVE-2026-102367: mall4j through 4.0 Insufficient Session Expiration via Token Refresh
Published Sep 28, 2026
·Updated
mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.
Affected Software
1 affected component
mall4j mall4j<=4.0
Event History
Sep 28, 2026
CVE Published
via MITRE·11:34 PM
Data Sourced
via MITRE·11:34 PM
DescriptionSeverityWeakness
Sep 29, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does this issue allow an unauthenticated user to obtain access?
The available information describes renewal of existing sessions for disabled accounts. It does not indicate that unauthenticated users can create a session through the affected endpoint.
2
Why might disabling an account fail to contain access?
The token refresh endpoint does not validate the account enabled flag when issuing a new session. A disabled account can therefore continue renewing its existing session through POST /token/refresh.