PT-2026-40035 · Pocket Id · Pocket-Id
Published
2026-05-12
·
Updated
2026-05-13
·
CVE-2026-43983
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Pocket ID versions prior to 2.6.0
Description
The
createTokenFromRefreshToken() function in oidc service.go validates the cryptographic integrity of refresh tokens but fails to re-verify the user's current authorization state before issuing new tokens. This flaw allows clients to refresh tokens indefinitely after authorization has been revoked, enables refresh tokens to remain functional after an account is disabled, and allows tokens to work even after a client is removed from a group.Recommendations
Update to version 2.6.0.
Exploit
Fix
Insufficient Session Expiration
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pocket-Id