{"id":"CVE-2026-71206","summary":"shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion","details":"Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase.","modified":"2026-08-12T03:51:39.937070240Z","published":"2026-08-05T06:59:06.908Z","database_specific":{"cna_assigner":"TuranSec","cwe_ids":["CWE-613"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71206.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71206.json"},{"type":"ADVISORY","url":"https://github.com/go-shiori/shiori"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71206"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/go-shiori/shiori","events":[{"introduced":"0"},{"last_affected":"707ea8215b63665311908bb22710186c0507123e"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0"}],"source":"AFFECTED_FIELD"}}],"versions":["0","v0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71206.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"}]}