Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
CVE: CVE-2026-22706 CVSS v3.1 Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N (2.1 — Low) Affected Versions: @strapi/admin and @strapi/plugin-users-permissions <=5.33.2 How to Patch: Immediately update your Strapi to >=5.33.3