Retour à la veille

CVE-2026-90562

Publié : 13 septembre 2026
Modifié : 13 septembre 2026
Lien officiel NVD
Score CVSS
8.1
HIGH

Description détaillée

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Références et Patchs