Description
Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. MyRezzta allows Password Recovery Exploitation.

This issue affects MyRezzta: from 2.06.03 before 2.07.01.
Published: 2026-10-08
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Remote Account Takeover via Brute-Forced Password Reset
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is caused by a weak password recovery mechanism that allows attackers to brute-force the reset code and take over any user account. By repeatedly requesting password reset links or codes, an attacker can guess a valid token and then set a new password, thereby gaining full access to the targeted account. The impact is a compromise of confidentiality, integrity, and availability of the compromised accounts.

Affected Systems

The affected product is AKIN Software’s MyRezzta. Versions from 2.06.03 up to, but not including, 2.07.01 contain the flaw.

Risk and Exploitability

The CVSS score of 9.1 indicates a very high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of mitigation measures such as rate limiting means attackers can successfully exploit the weakness. The likely attack vector is remote through the publicly accessible password reset functionality, requiring no special privileges beyond sending repeated reset requests.

Generated by OpenCVE AI on October 8, 2026 at 14:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MyRezzta to version 2.07.01 or newer, where the password reset mechanism has been secured.
  • If an upgrade is not immediately possible, implement brute‑force protection on the reset endpoint by adding rate limiting, CAPTCHA challenges, or temporary account lockout after several failed reset attempts.
  • Continuously monitor reset logs for anomalous activity and block IPs or user accounts that exhibit suspicious reset behavior.

Generated by OpenCVE AI on October 8, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. MyRezzta allows Password Recovery Exploitation. This issue affects MyRezzta: from 2.06.03 before 2.07.01.
Title Password Reset Code Brute Force Leading to Account Takeover in AKIN Software's MyRezzta
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-10-08T14:12:26.270Z

Reserved: 2026-08-07T08:50:33.629Z

Link: CVE-2026-19218

cve-icon Vulnrichment

Updated: 2026-10-08T14:12:23.124Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T13:17:16.753

Modified: 2026-10-08T20:09:14.010

Link: CVE-2026-19218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:45:17Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password