Medium severity5.3NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-61452
CVE-2026-61452
Description
The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour) regardless of logout, password change, new token issuance, or account disablement. An attacker who has stolen an access token retains full API access until the token naturally expires.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <2.0.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.