CVE-2026-108785 | macrozheng mall up to 1.0.3 JwtAuthenticationTokenFilter /admin/refreshToken JwtTokenUtil.refreshHeadToken token session expiration (Issue 997)

SecurityVulns

A vulnerability was found in macrozheng mall up to 1.0.3. It has been rated as critical. This issue affects the function JwtTokenUtil.refreshHeadToken of the file /admin/refreshToken of the component JwtAuthenticationTokenFilter. This manipulation of the argument token causes session expiration.

This vulnerability appears as CVE-2026-108785. The attack may be initiated remotely. In addition, an exploit is available.

To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More