What is CVE-2026-39924?
CVE-2026-39924 is an improper session invalidation vulnerability in Flarum prior to version 1.8.16. It allows attackers with a valid session token to retain full account access even after the victim changes their password, because the `access_tokens` table is never cleared on password change events. Users should upgrade to the latest version to mitigate the risk.
Azərbaycanca: CVE-2026-39924 Flarum platformunun 1.8.16 versiyasından əvvəlki versiyalarında mövcud olan düzgün olmayan sessiya ləğvetmə zəifliyidir. Bu zəiflik, istifadəçi şifrəsini dəyişdikdən sonra belə, etibarlı sessiya tokeninə sahib olan təcavüzkarların hesaba tam girişi saxlaya bilməsinə imkan verir. Problemin səbəbi, şifrə dəyişikliyi hadisələrində `access_tokens` cədvəlinin təmizlənməməsidir — Flarum-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the Flarum platform are affected by CVE-2026-39924?
This vulnerability exists in all versions of Flarum prior to version 1.8.16.
What is the risk of the `access_tokens` table not being cleared in CVE-2026-39924?
It allows attackers with a valid session token to retain full account access even after the password is changed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.