Junglewise Threat Intelligence

CVE-2026-86698: Hex Package Manager insufficient session expiration in OAuth token issuance

CVE-2026-86698 · Severity: info · Published 2026-09-22

Technologies: Hex (Hex). Vendors: Hex.

Executive brief

Hex.pm is a package manager for the Erlang ecosystem used by Elixir and Erlang developers. A user who has been removed from an organization or whose session has been revoked can continue accessing that organization's private packages and documentation for up to 30 days by reusing a retained refresh token, even though their access should have been revoked immediately.

Technical details

The refresh token in Hex.pm's OAuth implementation carries the same repository scopes as the access token but has a 30-day expiration instead of 30 minutes. The CDN service that serves private repositories authorizes access based on token scope claims without database lookups, allowing stale tokens to remain valid until natural expiration. Removing organization membership or revoking a session takes effect only when the refresh token expires, not immediately.

Affected products

  • Hex hex.pm from 2025-10-10 before 2026-09-22

Timeline

  • 2026-09-22: disclosed
  • 2026-09-22: patched

References