CVE-2026-93340
6.8 MEDIUMpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows unauthenticated attackers to exploit a password reset link poisoning vulnerability by manipulating the client-supplied origin parameter, leading to potential full account takeover.
- Exploitability
- Exploitation is relatively easy as it requires sending a crafted request with an attacker-controlled origin parameter without server-side validation.
- Blast radius
- If exploited, this can result in unauthorized access and control over any user's account, including administrator accounts, leading to significant data breaches.
- Prioritized remediation
- Update Gladys Assistant to version 5.1.0 or later to address the vulnerability.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to receive a poisoned reset link that discloses the session token to the attacker, enabling full account takeover including administrator accounts.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Weaknesses
CWE-640
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-9273
- HIGHCVE-2026-94412PoC
- MEDIUMCVE-2026-94533PoC
- MEDIUMCVE-2025-71420PoC
- CRITICALCVE-2026-10050PoC
- MEDIUMCVE-2026-14465
- HIGHCVE-2026-14553
- MEDIUMCVE-2026-14816
Related by shared AI tags and CWE weakness class. Browse the full archive.