Junglewise Threat Intelligence

CVE-2026-81826: Flowintel session fixation after password change

CVE-2026-81826 · Severity: info · CVSS 0 · Published 2026-08-27

Technologies: FlowIntel. Vendors: FlowIntel.

Executive brief

Flowintel is a threat intelligence platform that manages user accounts and authentication sessions. When a user changes their password, the application fails to invalidate existing login sessions, allowing attackers with a stolen or compromised session token to remain authenticated even after the password is changed. This could enable prolonged unauthorized access to sensitive intelligence data if an attacker had previously obtained valid credentials or session information.

Technical details

The vulnerability is a session fixation issue in the password change functionality. When a user changes their password via edit_user_core() or admin_edit_user_core(), the new password is stored in the database but existing authenticated sessions are not revoked. An attacker in possession of a valid session token (via theft, interception, or prior compromise) can continue using that token to maintain authenticated access until the session expires naturally. The fix explicitly calls _invalidate_user_sessions(user.id) after password updates to ensure all existing sessions are terminated. This is a network-accessible vulnerability affecting authenticated users or attackers with valid session tokens.

Affected products

  • Flowintel Flowintel >=3.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-24: patched: Fix committed upstream

References

Related threats