HIGH

CVE-2026-90562

2026-09-13 CVSS v3.1
CVSS
8.1

Description

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.

Weakness (CWE)

CWE-331

EPSS Score

0.42%
Probability of exploitation in next 30 days
36.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE