Security Advisory

CVE-2026-61452

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-15 11:25:45
Last updated 2026-07-15 13:52:28
Assigner VulnCheck
CVSS score 6.9
State PUBLISHED

Description

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour) regardless of logout, password change, new token issuance, or account disablement. An attacker who has stolen an access token retains full API access until the token naturally expires.