PT-2026-40035 · Pocket Id · Pocket-Id

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2026-43983

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pocket ID versions prior to 2.6.0
Description The createTokenFromRefreshToken() function in oidc service.go validates the cryptographic integrity of refresh tokens but fails to re-verify the user's current authorization state before issuing new tokens. This flaw allows clients to refresh tokens indefinitely after authorization has been revoked, enables refresh tokens to remain functional after an account is disabled, and allows tokens to work even after a client is removed from a group.
Recommendations Update to version 2.6.0.

Exploit

Fix

Insufficient Session Expiration

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43983

Affected Products

Pocket-Id