Description
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation.

This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized account takeover via weak password recovery
Action: Apply Patch
AI Analysis

Impact

This vulnerability arises from an inadequate password recovery mechanism in LIBRID/LIBREF, allowing attackers to reset user passwords without proper authentication. The flaw falls under CWE‑640, indicating improper authentication. An attacker exploiting this can gain unauthorized access to user accounts, potentially leading to data leakage, privilege escalation, or further compromise of the system.

Affected Systems

The affected product is Ankaref Innovation and Technology Inc.’s LIBRID/LIBREF. Versions from 2.01.0.2183 through 10092026 are vulnerable.

Risk and Exploitability

The CVSS score is 7.5, reflecting a high potential impact. No EPSS score is available, and the issue is not currently listed in the CISA KEV catalog. The likely attack vector is remote via the web interface’s password recovery feature, which an attacker can target after determining a username or email address. Given the lack of mitigation in the source code, exploitation is reasonably straightforward for an individual with information about a target account.

Generated by OpenCVE AI on September 10, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether Ankaref has released a patch that fixes the weak password recovery mechanism and deploy it immediately.
  • If no patch is available, disable the password recovery feature or enforce multi‑factor authentication for account recovery to reduce the attack surface.
  • Prompt all users to reset their passwords and enforce a strong password policy to minimize the risk of credential reuse or weak passwords.

Generated by OpenCVE AI on September 10, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Improper Authentication in Ankaref's LIBRID/LIBREF
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-10T17:03:26.224Z

Reserved: 2026-04-14T15:20:33.522Z

Link: CVE-2026-6285

cve-icon Vulnrichment

Updated: 2026-09-10T17:03:18.461Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T14:17:05.850

Modified: 2026-09-10T17:17:05.560

Link: CVE-2026-6285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T14:45:18Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password