CVE-2026-100502

CVE-2026-100502 published: Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint nea...

View full NVD advisory → ← Back to CVE watch