← Back to search

CVE-2026-93340

6.8 MEDIUMpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows unauthenticated attackers to exploit a password reset link poisoning vulnerability by manipulating the client-supplied origin parameter, leading to potential full account takeover.
Exploitability
Exploitation is relatively easy as it requires sending a crafted request with an attacker-controlled origin parameter without server-side validation.
Blast radius
If exploited, this can result in unauthorized access and control over any user's account, including administrator accounts, leading to significant data breaches.
Prioritized remediation
Update Gladys Assistant to version 5.1.0 or later to address the vulnerability.
auth-bypasswebpassword-resetvulnerability

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to receive a poisoned reset link that discloses the session token to the attacker, enabling full account takeover including administrator accounts.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Weaknesses

CWE-640

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.