# Possible Security Vulnerability – Existing Sessions Do Not Require the New Password

**URL:** <https://discourse.shapr3d.com/t/possible-security-vulnerability-existing-sessions-do-not-require-the-new-password/41696>\
**Category:** Technical issues and bugs\
**Created:** [September 29, 2026, 8:16am UTC](https://discourse.shapr3d.com/t/possible-security-vulnerability-existing-sessions-do-not-require-the-new-password/41696 "2026-09-29T08:16:30Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![kontakt](https://avatars.discourse-cdn.com/v4/letter/k/22d042/32.png) [@kontakt](https://discourse.shapr3d.com/u/kontakt)\
**Post date:** [September 29, 2026, 8:16am UTC](https://discourse.shapr3d.com/t/possible-security-vulnerability-existing-sessions-do-not-require-the-new-password/41696/1 "2026-09-29T08:16:30Z")

</div>

Hello everyone,

I would like to report a potential security issue regarding account authentication and session management in Shapr3D.

About 1.5 weeks ago, one of my accounts was compromised and my passwords were stolen. As a result, I logged out of all my devices and changed my passwords everywhere.

However, I noticed some behavior with Shapr3D that I believe could be security-relevant:

**Changing the account password does not appear to invalidate existing Shapr3D sessions on already logged-in devices.**

If a device is already logged into Shapr3D and the account password is subsequently changed, the Shapr3D application can still be used on that device without requiring the new password to be entered again.

This could potentially be intentional, for example if existing sessions are designed to remain active. However, it becomes a security concern if a device has been compromised or is still accessible to someone else. In that situation, simply changing the password does not appear to be sufficient to revoke access to the Shapr3D account.

I also noticed the following behavior:

- Several devices are already logged into the account.
- If the maximum number of logged-in devices is exceeded, Shapr3D asks the user to log in again or remove/log out another device.
- On a device that was already authenticated, it is apparently possible to access the account again **without entering the current password**.
- This means that even after changing the account password, an existing session or authentication token appears to remain valid and can still be used to access the account.

### Why I consider this potentially security-relevant

If an attacker has access to an already authenticated device or an existing Shapr3D session, changing the account password may not be sufficient to revoke that access.

After an account compromise, it would be useful to have a way to **invalidate all existing authentication sessions server-side** , so that every device is required to authenticate again using the current password.

I do not know whether this behavior is intentional or whether it is actually a security vulnerability. Therefore, I am reporting it as a potential security issue so that the Shapr3D team can investigate it.

**The key question is:**  
Should changing an account password invalidate all existing authentication sessions, or should there at least be an option to force all devices/sessions to log in again?

If not, I believe a feature such as **“Log out of all devices” / “Terminate all sessions”** would be useful, especially in the event that an account has been compromised.

I would appreciate clarification as to whether this behavior is known and intentional, or whether it could be a problem with Shapr3D’s session management.
