Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 28, 2026
Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens
CVE-2026-61452
Description
The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour) regardless of logout, password change, new token issuance, or account disablement. An attacker who has stolen an access token retains full API access until the token naturally expires.
Affected products
2- Range: <2.0.4
Patches
Vulnerability mechanics
References
2- github.com/getgrav/grav/security/advisories/GHSA-m8g9-wxhx-6f86mitrevendor-advisory
- www.vulncheck.com/advisories/grav-before-improper-session-invalidation-jwt-access-tokensmitrethird-party-advisory
News mentions
0No linked articles in our index yet.