CVE-2026-102367: mall4j through 4.0 Insufficient Session Expiration via Token Refresh

Published Sep 28, 2026
·
Updated

mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove.

Affected Software

1 affected component
mall4j mall4j<=4.0

Event History

Sep 28, 2026
CVE Published
via MITRE·11:34 PM
Data Sourced
via MITRE·11:34 PM
DescriptionSeverityWeakness
Sep 29, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Does this issue allow an unauthenticated user to obtain access?

The available information describes renewal of existing sessions for disabled accounts. It does not indicate that unauthenticated users can create a session through the affected endpoint.

2

Why might disabling an account fail to contain access?

The token refresh endpoint does not validate the account enabled flag when issuing a new session. A disabled account can therefore continue renewing its existing session through POST /token/refresh.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203