CVE-2026-39924: Flarum Framework

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.

Affected products

  • Flarum Flarum Framework: before 1.8.16 (fixed in 1.8.16)

Published 2026-08-05. Last modified 2026-09-09.