CVE-2026-81826
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
27/08/2026
Last modified:
27/08/2026
Description
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed.<br />
<br />
<br />
This means that if an attacker already possesses a valid session—for example, from prior access or a stolen session token—the victim changing their password does not terminate that attacker’s access. The session remains usable until it expires naturally. The upstream commit describes this directly as:<br />
<br />
<br />
“session keeps working until it expires.”<br />
<br />
The fix detects password changes and explicitly invokes _invalidate_user_sessions(user.id) after the database update. This is applied in both edit_user_core() and admin_edit_user_core().<br />
<br />
Version impacted >=3.3.0
Impact
Base Score 4.0
9.10
Severity 4.0
CRITICAL



