Junglewise Threat Intelligence

CVE-2026-46715: Pallets-Eco Flask-Security-Too OAuth reauthentication freshness bypass

CVE-2026-46715 · Severity: medium · CVSS 0 · Published 2026-07-20

Technologies: Flask-Security-Too (PyPI). Vendors: PyPI.

Executive brief

Flask-Security-Too is a library used to add security and authentication features to Flask web applications. A flaw in its OAuth reauthentication process allows an attacker who has access to a user's expired or 'stale' session to refresh that session's security status using their own social media or OAuth account. This could allow an unauthorized person to perform sensitive actions, such as changing a victim's username or account settings, without knowing the victim's actual credentials.

Technical details

An improper authentication vulnerability exists in Flask-Security-Too version 5.8.0 within the OAuth reauthentication flow. The `oauth_verify_response()` function in `flask_security/oauth_glue.py` fails to verify that the user identity returned by the OAuth provider matches the currently authenticated `current_user`. If an attacker can operate a stale but still authenticated victim session, they can complete the OAuth verification process using their own OAuth credentials. This updates the session's freshness timestamp (`fs_paa`), allowing the attacker to bypass 'freshness' requirements for sensitive routes like `/change-username`. The issue is resolved in version 5.8.1 by ensuring the OAuth-resolved email matches the session user.

Affected products

  • pallets-eco Flask-Security-Too >= 5.8.0, < 5.8.1

Timeline

  • 2026-05-17: advisory: GitHub Security Advisory published
  • 2026-05-20: patched: Fix committed to repository
  • 2026-07-20: disclosed: CVE published to NVD

References

Related threats