Description
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation.

This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized account takeover via weak password recovery
Action: Apply Patch
AI Analysis

Impact

The vulnerability is caused by a weak password recovery mechanism in Ankaref's LIBRID/LIBREF, which allows attackers to exploit the password reset functionality and recover lost user credentials. This flaw is categorized under CWE‑640 and permits unauthorized account takeover by resetting passwords without adequate authentication checks. An attacker who successfully triggers the recovery can access any user account, potentially exposing sensitive data, escalating privileges, or compromising the entire system.

Affected Systems

The affected product is Ankaref Innovation and Technology Inc.’s LIBRID/LIBREF. Versions from 2.01.0.2183 up to (but not including) 18.9.26.2319 are vulnerable.

Risk and Exploitability

The CVSS score is 7.5, reflecting a high potential impact. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability. The issue is not currently listed in the CISA KEV catalog. The likely attack vector is remote via the web interface’s password recovery feature, which an attacker can target after determining a username or email address. Given the lack of mitigation in the source code, exploitation is reasonably straightforward for an individual with information about a target account.

Generated by OpenCVE AI on September 23, 2026 at 17:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify whether Ankaref has released a patch that fixes the weak password recovery mechanism and deploy it immediately.
  • If no patch is available, disable the password recovery feature or enforce multi‑factor authentication for account recovery to reduce the attack surface.
  • Prompt all users to reset their passwords and enforce a strong password policy to minimize the risk of credential reuse or weak passwords.

Generated by OpenCVE AI on September 23, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ankaref Innovation And Technology Inc.
Ankaref Innovation And Technology Inc. librid/libref
Vendors & Products Ankaref Innovation And Technology Inc.
Ankaref Innovation And Technology Inc. librid/libref

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Improper Authentication in Ankaref's LIBRID/LIBREF
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ankaref Innovation And Technology Inc. Librid/libref
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-23T08:18:39.252Z

Reserved: 2026-04-14T15:20:33.522Z

Link: CVE-2026-6285

cve-icon Vulnrichment

Updated: 2026-09-10T17:03:18.461Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T14:17:05.850

Modified: 2026-09-23T09:17:08.877

Link: CVE-2026-6285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T17:45:07Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password