Loading market data...
← Back to CVE feed

CVE-2026-75103

HIGH CVSS 8.8 View on NVD ↗

Description

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: Aug 17, 2026 21:16 UTC Modified: Aug 17, 2026 21:16 UTC