Summary
The refresh endpoint validates the signature of the supplied token but never checks that the subject claim matches the session presenting it. Any authenticated user can mint a valid access token for any other account.
Impact
Verified end to end against a seeded test account: full read and write access to another tenant's data, including billing records. Exploitable without user interaction from the public internet.
Remediation
Bind the refresh token to the authenticated session server-side and reject any token whose subject does not match. Patch and rotation guidance supplied with the finding.