Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to receive a poisoned reset link that discloses the session token to the attacker, enabling full account takeover including administrator accounts. | |
| Title | Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint | |
| Weaknesses | CWE-640 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T21:21:58.925Z
Reserved: 2026-09-17T18:41:40.757Z
Link: CVE-2026-93340
No data.
Status : Received
Published: 2026-09-21T22:16:59.547
Modified: 2026-09-21T22:16:59.547
Link: CVE-2026-93340
No data.
OpenCVE Enrichment
No data.
