Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.2

HyperCloud versions 2.3.5-2.6.8 allow unauthorized access with expired tokens

CVE-2026-1842
Summary

HyperCloud versions 2.3.5 through 2.6.8 contain a security issue that allows users to access resources with expired or invalid tokens. This could lead to unauthorized access if a token is leaked or compromised. To protect your account, update to a fixed version of HyperCloud.

Original title
HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a refresh token was u...
Original description
HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a refresh token was used. Because refresh tokens have a significantly longer lifetime (default one year), an authenticated client could use a refresh token in place of an access token to maintain long-term access without token rotation. Additionally, old access tokens remained valid after refresh, enabling concurrent or extended use beyond intended session boundaries. This vulnerability could allow prolonged unauthorized access if a token is disclosed.
nvd CVSS4.0 6.2
Vulnerability type
CWE-613
Published: 20 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026